Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Avada Plugin Threatens 1 Million Sites

Critical Flaw in Avada Plugin Threatens 1 Million Sites

Posted on June 19, 2026 By CWS

A severe security flaw in the popular Avada Builder WordPress plugin has put over a million websites at risk of file deletion attacks, which could lead to complete site takeover and remote code execution. Known as CVE-2026-8713 and carrying a CVSS score of 9.1, this vulnerability was identified by security researcher ‘daroo’ through the Wordfence Bug Bounty Program.

Discovery and Impact of the Vulnerability

The researcher received a $3,600 reward for uncovering the vulnerability, which affects all versions of the plugin up to 3.15.3. A patch was released in version 3.15.4 to address this critical issue. The problem originates from inadequate validation of file paths within the plugin’s file deletion function, allowing attackers to exploit a path-traversal flaw.

Malicious actors can utilize Avada’s form builder, especially when configured to store submissions in the database, to delete arbitrary server files. By submitting a crafted payload with directory traversal sequences, attackers can target files beyond the intended file upload directory, posing a significant threat to site security.

Mechanism of the Attack

The attack requires an Avada form that is publicly accessible and has database storage enabled. An attacker can submit a malicious form entry, manipulating file paths to target critical files like wp-config.php. Wordfence’s firewall is capable of detecting and blocking such path traversal attempts.

Due to insufficient validation checks, the plugin processes harmful inputs during its automated privacy cleanup routine, leading to the deletion of targeted files. Attackers can trigger this routine without needing authentication or administrative access, potentially reconfiguring the site with malicious intent.

Response and Recommendations

The vulnerability was reported to Wordfence on May 13, 2026, verified and communicated to the plugin vendor on May 15, and addressed by the Avada team with a patch released on June 2, 2026, in version 3.15.4. Users are strongly encouraged to update to the latest version to protect against exploitation.

This incident underscores the critical importance of secure coding practices and thorough input validation in plugin development. Without proper checks, attackers can manipulate directory paths, enabling unauthorized file deletions. The widespread use and ease of exploitation make this vulnerability particularly dangerous.

Wordfence users benefit from built-in firewall rules designed to detect and prevent such attacks, highlighting the tool’s role in safeguarding WordPress sites. Ensuring plugins are updated and employing comprehensive security measures are vital steps in maintaining site integrity and thwarting potential threats.

Cyber Security News Tags:Avada Plugin, CVE-2026-8713, Cybersecurity, file deletion, plugin update, remote code execution, security vulnerability, site security, Wordfence, WordPress

Post navigation

Previous Post: Critical LiteSpeed cPanel Vulnerability Added to CISA List
Next Post: Unpatchable usbliter8 Exploit Affects Apple Devices

Related Posts

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Cyber Security News
WhatsApp Vulnerabilities Leaks User’s Metadata Including Device’s Operating System WhatsApp Vulnerabilities Leaks User’s Metadata Including Device’s Operating System Cyber Security News
GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack Cyber Security News
Better Auth API keys Vulnerability Let Attackers Create Privileged Credentials For Arbitrary Users Better Auth API keys Vulnerability Let Attackers Create Privileged Credentials For Arbitrary Users Cyber Security News
Securing the Cloud Best Practices for Multi-Cloud Environments Securing the Cloud Best Practices for Multi-Cloud Environments Cyber Security News
Cybercriminals Exploit AI to Distribute macOS Malware Cybercriminals Exploit AI to Distribute macOS Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark