A critical security vulnerability has been discovered in the widely used Avada (Fusion) Builder WordPress plugin, potentially putting more than one million websites at risk. Tracked as CVE-2026-8713 and assigned a CVSS severity score of 9.1, the flaw affects all versions up to and including 3.15.3. Security researcher daroo identified the issue and reported it through the Wordfence Bug Bounty Program, earning a reward of $3,600. The vulnerability has since been fixed in version 3.15.4. The issue originates from inadequate file path validation in the plugin’s maybe_delete_files() function, which is part of the form submission and privacy cleanup system. Avada Builder allows website owners to store form submissions in a database and automatically delete or anonymize records after a specified period. However, the cleanup mechanism fails to properly sanitize and normalize file paths, making it vulnerable to path traversal attacks. An attacker can exploit this weakness by submitting specially crafted form data containing malicious file paths. Because the plugin does not enforce directory restrictions, these manipulated paths can point to files outside the intended uploads directory. When the cleanup process runs, the attacker controlled path is converted into a server file path and passed to WordPress’s file deletion function, enabling arbitrary file deletion. Exploitation requires only a publicly accessible Avada form configured to store submissions, and no authentication or administrator interaction is needed. The consequences can be severe. By deleting critical files such as wp-config.php, attackers can force WordPress into its installation state, potentially allowing them to reconfigure the site, deploy malicious code, and gain full control of the server. Wordfence has confirmed that its firewall can block exploitation attempts. Website administrators are strongly urged to update to Avada Builder version 3.15.4 immediately, review exposed forms, deploy web application firewall protections, and monitor systems for suspicious activity or unexpected file deletions.
Tata Electronics has confirmed that it recently experienced a cybersecurity incident, affecting portions of its information technology environment. According to the company, the is...
Phishing attacks continue to evolve, incorporating advanced techniques such as multi-stage redirects, dynamically loaded content, embedded iframes, and browser-executed scripts. Th...
India based automotive manufacturer Bajaj Auto has disclosed a ransomware incident that impacted its corporate IT environment and the systems of its technology subsidiary, Bajaj Au...