Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Avada Plugin Threatens 1 Million Sites

Critical Flaw in Avada Plugin Threatens 1 Million Sites

Posted on June 19, 2026 By CWS

A severe security flaw in the popular Avada Builder WordPress plugin has put over a million websites at risk of file deletion attacks, which could lead to complete site takeover and remote code execution. Known as CVE-2026-8713 and carrying a CVSS score of 9.1, this vulnerability was identified by security researcher ‘daroo’ through the Wordfence Bug Bounty Program.

Discovery and Impact of the Vulnerability

The researcher received a $3,600 reward for uncovering the vulnerability, which affects all versions of the plugin up to 3.15.3. A patch was released in version 3.15.4 to address this critical issue. The problem originates from inadequate validation of file paths within the plugin’s file deletion function, allowing attackers to exploit a path-traversal flaw.

Malicious actors can utilize Avada’s form builder, especially when configured to store submissions in the database, to delete arbitrary server files. By submitting a crafted payload with directory traversal sequences, attackers can target files beyond the intended file upload directory, posing a significant threat to site security.

Mechanism of the Attack

The attack requires an Avada form that is publicly accessible and has database storage enabled. An attacker can submit a malicious form entry, manipulating file paths to target critical files like wp-config.php. Wordfence’s firewall is capable of detecting and blocking such path traversal attempts.

Due to insufficient validation checks, the plugin processes harmful inputs during its automated privacy cleanup routine, leading to the deletion of targeted files. Attackers can trigger this routine without needing authentication or administrative access, potentially reconfiguring the site with malicious intent.

Response and Recommendations

The vulnerability was reported to Wordfence on May 13, 2026, verified and communicated to the plugin vendor on May 15, and addressed by the Avada team with a patch released on June 2, 2026, in version 3.15.4. Users are strongly encouraged to update to the latest version to protect against exploitation.

This incident underscores the critical importance of secure coding practices and thorough input validation in plugin development. Without proper checks, attackers can manipulate directory paths, enabling unauthorized file deletions. The widespread use and ease of exploitation make this vulnerability particularly dangerous.

Wordfence users benefit from built-in firewall rules designed to detect and prevent such attacks, highlighting the tool’s role in safeguarding WordPress sites. Ensuring plugins are updated and employing comprehensive security measures are vital steps in maintaining site integrity and thwarting potential threats.

Cyber Security News Tags:Avada Plugin, CVE-2026-8713, Cybersecurity, file deletion, plugin update, remote code execution, security vulnerability, site security, Wordfence, WordPress

Post navigation

Previous Post: Critical LiteSpeed cPanel Vulnerability Added to CISA List
Next Post: Unpatchable usbliter8 Exploit Affects Apple Devices

Related Posts

2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware 2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware Cyber Security News
Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Tactics Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Tactics Cyber Security News
GnuTLS 3.8.13 Update: Key Security Vulnerabilities Fixed GnuTLS 3.8.13 Update: Key Security Vulnerabilities Fixed Cyber Security News
Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks Cyber Security News
North Korean Malware Evades Detection with New Tactics North Korean Malware Evades Detection with New Tactics Cyber Security News
Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark