PT-2026-50846 · WordPress · Avada Builder
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avada (Fusion) Builder versions prior to 3.15.4
Description
The Avada (Fusion) Builder plugin for WordPress contains a flaw allowing unauthenticated attackers to delete arbitrary files on the server. This issue stems from insufficient file path validation within the
maybe delete files() function. Exploitation can lead to remote code execution if critical files, such as wp-config.php, are deleted. An estimated 1,000,000 devices are potentially affected worldwide. The attack requires a published Avada form configured to save entries to the database. An attacker can submit a path-traversal payload via the wp ajax nopriv fusion form submit ajax endpoint while manipulating the fusion privacy expiration interval and privacy expiration action variables to trigger an immediate cleanup. This process causes the entry to be handled by the Fusion Form DB Privacy shutdown-hook routine without administrator interaction.Recommendations
Update Avada (Fusion) Builder to version 3.15.4.
Fix
RCE
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avada Builder