logo

Avada Builder Flaws Expose One Million WordPress Sites

ID: 5f6a9fc9-451a-54ed-b016-bf0a4c75198e

STIX ID: report--5f6a9fc9-451a-54ed-b016-bf0a4c75198e

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

...
...

## Executive summary Two vulnerabilities in the Avada Builder WordPress plugin were disclosed and patched: CVE-2026-4782 (authenticated arbitrary file read via an SVG shortcode allowing exposure of files like wp-config.php) and CVE-2026-4798 (unauthenticated time-based SQL injection via the product_order parameter on sites that previously had WooCommerce). The vendor released fixes (3.15.2/3.15.3) and site owners are advised to update immediately, audit subscriber accounts, rotate credentials if compromise is suspected, and check for suspicious ajax traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.