PT-2026-50846 · WordPress · Avada Builder

·

CVE-2026-8713

·

Published

2026-06-18

·

Updated

2026-07-13

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avada (Fusion) Builder versions prior to 3.15.4
Description The Avada (Fusion) Builder plugin for WordPress contains a flaw allowing unauthenticated attackers to delete arbitrary files on the server. This issue stems from insufficient file path validation within the maybe delete files() function. Exploitation can lead to remote code execution if critical files, such as wp-config.php, are deleted. An estimated 1,000,000 devices are potentially affected worldwide. The attack requires a published Avada form configured to save entries to the database. An attacker can submit a path-traversal payload via the wp ajax nopriv fusion form submit ajax endpoint while manipulating the fusion privacy expiration interval and privacy expiration action variables to trigger an immediate cleanup. This process causes the entry to be handled by the Fusion Form DB Privacy shutdown-hook routine without administrator interaction.
Recommendations Update Avada (Fusion) Builder to version 3.15.4.

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8713

Affected Products

Avada Builder