Avada Builder WordPress plugin arbitrary file read and SQL injection flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-4782 and CVE-2026-4798 in the Avada Builder WordPress plugin expose roughly one million sites to arbitrary file read and SQL injection risk. The file-read flaw can expose sensitive server files such as wp-config.php, while the SQL injection flaw is unauthenticated and affects `product_order` on sites with WooCommerce previously installed and deactivated. A fix was shipped in Avada Builder 3.15.3 after an initial patch in 3.15.2.
Related Happenings
WordPress.org closes compromised EssentialPlugin plugins with forced update
Security Tool/Service
First: 15.04.2026 23:33
Last: 15.04.2026 23:33
Sources 1
About this happening:
**WordPress.org** closed the compromised **EssentialPlugin** plugins and forced an update, changing how affected sites received and ran the package. The move mattered because the...
WordPress.org closes compromised EssentialPlugin plugins with forced update
Security Tool/ServiceAbout this happening: **WordPress.org** closed the compromised **EssentialPlugin** plugins and forced an update, changing how affected sites received and ran the package. The move mattered because the...
Timeline
-
13.05.2026 17:00 1 articles · 14d ago
Rafie Muhammad reports two Avada Builder CVEs
Technical Analysis UpdateIndependent researcher Rafie Muhammad reports CVE-2026-4782 and CVE-2026-4798 in the Avada Builder WordPress plugin through the Wordfence Bug Bounty Program, starting the remediation timeline for the affected software.
Show sources
- Avada Builder Flaws Expose One Million WordPress Sites — www.infosecurity-magazine.com — 13.05.2026 17:00
-
13.05.2026 17:00 1 articles · 14d ago
Wordfence shares full disclosure and Avada starts fix work
Mitigation Patch UpdateWordfence shares full disclosure with the Avada team, and the vendor begins work on a fix for the Avada Builder WordPress plugin vulnerabilities.
Show sources
- Avada Builder Flaws Expose One Million WordPress Sites — www.infosecurity-magazine.com — 13.05.2026 17:00
-
13.05.2026 17:00 1 articles · 14d ago
Avada Builder 3.15.2 ships the initial patch
Mitigation Patch UpdateAvada releases version 3.15.2 as the first patch for the Avada Builder WordPress plugin vulnerabilities, beginning remediation before the later complete fix.
Show sources
- Avada Builder Flaws Expose One Million WordPress Sites — www.infosecurity-magazine.com — 13.05.2026 17:00
-
13.05.2026 17:00 2 articles · 14d ago
Wordfence warns that Avada Builder flaws affect around one million sites
Victim Impact UpdateWordfence warns that CVE-2026-4782 and CVE-2026-4798 in the Avada Builder WordPress plugin place around one million sites at risk of arbitrary file read and SQL injection attacks, and Avada Builder version 3.15.3 provides the complete fix.
Show sources
- Avada Builder Flaws Expose One Million WordPress Sites — www.infosecurity-magazine.com — 13.05.2026 17:00
- Avada Builder WordPress plugin flaws allow site credential theft — www.bleepingcomputer.com — 15.05.2026 18:56