Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/Critical WordPress Plugin Bug Exposes 1M Sites to File Deletion
CyberSecurity News

Critical WordPress Plugin Bug Exposes 1M Sites to File Deletion

Key Takeaways A critical vulnerability (CVE-2026-8713) in the Avada (Fusion) Builder WordPress plugin allows unauthenticated attackers to delete arbitrary files. Over one million websites using Avada...

Marcus Rodriguez
Marcus Rodriguez
June 19, 2026 3 Min Read
52 0

Key Takeaways

  • A critical vulnerability (CVE-2026-8713) in the Avada (Fusion) Builder WordPress plugin allows unauthenticated attackers to delete arbitrary files.
  • Over one million websites using Avada Builder versions up to 3.15.3 are exposed to potential full site compromise and remote code execution.
  • The flaw, with a CVSS score of 9.1, was discovered by “daroo” and has been patched in Avada Builder version 3.15.4.

Critical Avada WordPress Plugin Bug Exposes Million Sites to File Deletion

A severe security flaw has been identified within the widely deployed Avada (Fusion) Builder WordPress plugin, leaving more than one million websites susceptible to arbitrary file deletion attacks. This vulnerability could lead to complete site compromise and potentially enable remote code execution.

Table Of Content

  • Key Takeaways
  • Critical Avada WordPress Plugin Bug Exposes Million Sites to File Deletion
  • Technical Details of the Avada WordPress Plugin Vulnerability
  • Disclosure and Patch Information
  • What You Should Do

The vulnerability, designated as CVE-2026-8713 and assigned a critical CVSS score of 9.1, was brought to light by security researcher “daroo” through the Wordfence Bug Bounty Program. The researcher was awarded $3,600 for their discovery. The issue impacts all plugin versions up to 3.15.3, with a fix implemented in version 3.15.4.

Technical Details of the Avada WordPress Plugin Vulnerability

The core of the problem lies in inadequate file path validation within the plugin’s maybe_delete_files() function, which handles file deletion logic. This oversight permits unauthenticated attackers to exploit a path traversal vulnerability, enabling them to delete any file on the server.

Attackers can leverage Avada’s form builder feature, specifically when a form is configured to store submissions directly in the database. By submitting a specially crafted payload containing directory traversal sequences, an attacker can manipulate file paths to target sensitive files located outside the intended upload directory.

The attack scenario requires an Avada form that is publicly accessible and has database storage enabled. An attacker would submit a malicious form entry containing a path similar to /wp-content/uploads/fusion-forms/../../../wp-config.php. Due to the absence of proper validation checks, the plugin processes this input during its automated privacy cleanup routine. Subsequently, WordPress’s native file deletion function is invoked to remove the targeted file.

Crucially, the attacker can trigger this cleanup process instantly by controlling specific form parameters, eliminating the need for any authentication or administrator interaction. Deleting vital files, such as wp-config.php, can force WordPress into a setup state. This allows attackers to reconfigure the site using a malicious database, ultimately resulting in a full site takeover and remote code execution capabilities.

Given the widespread adoption of the Avada plugin and the relative ease of exploitation, this vulnerability presents a significant risk to all affected websites.

Disclosure and Patch Information

The vulnerability was initially reported to Wordfence on May 13, 2026. Following validation, the details were disclosed to the Avada vendor on May 15. The Avada development team promptly patched the flaw on May 19, with the official release of Avada version 3.15.4 occurring on June 2, 2026. Wordfence users benefit from built-in firewall rules that automatically detect and block path traversal attempts in form submissions, providing immediate protection.

This incident underscores the persistent dangers associated with insufficient input validation in file-handling functions and emphasizes the critical importance of secure coding practices in plugin development. Without robust directory containment checks or secure file path resolution, systems remain vulnerable to traversal sequences that can escape intended directories, leading to arbitrary file deletion.

What You Should Do

  • Update Immediately: All users of the Avada (Fusion) Builder WordPress plugin must update to version 3.15.4 or higher without delay. Websites running older versions are at severe risk of active exploitation.
  • Verify Form Configurations: Review all Avada forms on your site to ensure they are configured securely, especially regarding database storage and public accessibility.
  • Implement Web Application Firewall (WAF): Utilize a robust WAF, such as Wordfence, to provide an additional layer of protection against path traversal and other common web attacks.
  • Regular Backups: Maintain regular, verified backups of your entire WordPress site, including both files and databases, to facilitate recovery in the event of a compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft June 2024 Patch Exposes Recycle Bin Filenames

Next Post

CISA Adds Critical LiteSpeed cPanel Plugin Vulnerability to KEV List

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us