FILTERING BY: CLEAR FILTER

Critical Unauthenticated Arbitrary File Deletion in Avada Builder CVE-2026-8713

CVE-2026-8713 is a critical arbitrary file deletion vulnerability affecting the Avada Builder (Fusion Builder) WordPress plugin. The flaw enables unauthenticated remote attackers to delete arbitrary files on the host server by exploiting improper input validation and missing authorization checks within the plugin's file-handling functions. This vulnerability poses a severe risk of widespread Denial of Service (DoS) or the removal of critical security configuration files, potentially facilitating further system compromise. Given an estimated install base exceeding one million websites, immediate patching is required to mitigate the risk of large-scale exploitation.


LINK COPIED TO CLIPBOARD