CVE Tools

1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)

Daily CyberSecurity (securityonline.info)By Do Son

PatchAvada Builder (Fusion)

Our summary

A critical vulnerability in themefusion Avada (Fusion) Builder, tracked as CVE-2026-8713 (CVSS 9.1), allows unauthenticated attackers to delete arbitrary files on affected servers without login. Versions at or below 3.15.3 are impacted, and the ability to remove sensitive files can lead to full compromise of a WordPress site. Site owners should upgrade to Avada Builder v3.15.4 or later immediately, even though there is no confirmed public exploitation reported yet.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store