{"id":13754,"date":"2026-06-20T10:04:20","date_gmt":"2026-06-20T10:04:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/20\/critical-wordpress-plugin-vulnerability-exposes-1-million-sites-to-file-deletion-attacks\/"},"modified":"2026-06-20T10:04:20","modified_gmt":"2026-06-20T10:04:20","slug":"critical-wordpress-plugin-vulnerability-exposes-1-million-sites-to-file-deletion-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/20\/critical-wordpress-plugin-vulnerability-exposes-1-million-sites-to-file-deletion-attacks\/","title":{"rendered":"Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks"},"content":{"rendered":"<p>    Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A critical security vulnerability in the widely used <a href=\"https:\/\/cybersecuritynews.com\/avada-builder-plugin-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Avada (Fusion) Builder WordPress plugin has exposed<\/a> over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution.<\/p>\n<p class=\"wp-block-paragraph\">The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1, was discovered by security researcher \u201cdaroo\u201d and reported through the Wordfence Bug Bounty Program.<\/p>\n<p class=\"wp-block-paragraph\">The researcher received a $3,600 reward for the finding. The vulnerability affects all plugin versions up to 3.15.3 and has been patched in version 3.15.4.<\/p>\n<h2 id=\"h-avada-wordpress-plugin-vulnerability\" class=\"wp-block-heading\">\n<strong>Avada<\/strong> <strong>WordPress Plugin Vulnerability<\/strong><br \/>\n<\/h2>\n<p class=\"wp-block-paragraph\">The issue stems from improper file path validation in the plugin\u2019s file-deletion logic in the\u00a0maybe_delete_files()\u00a0function. This flaw allows unauthenticated attackers to delete arbitrary files on the server by <a href=\"https:\/\/cybersecuritynews.com\/critical-wordpress-plugin-vulnerability-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">exploiting a path-traversal vulnerability<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Attackers can abuse Avada\u2019s form builder feature, specifically when a form is configured to store submissions in the database.<\/p>\n<p class=\"wp-block-paragraph\">By submitting a crafted payload containing directory traversal sequences, an attacker can manipulate file paths and target sensitive files outside the intended upload directory.<\/p>\n<p class=\"wp-block-paragraph\">The attack requires a publicly accessible Avada form with database storage enabled. An attacker submits a malicious form entry containing a path such as:<code> \/wp-content\/uploads\/fusion-forms\/..\/..\/..\/wp-config.php<\/code>.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEig37VwHNI7MUGpDTCp89d3WAFELZ_22GRwE37MiQ4oSEBaQDUqyBBdM1At_uzDUZjdfsRsx1VP_i8MhrdhP9PIXT0XiDTorFk0vB_U36TSl2AJPlyroLEBzUGvtpkfXGgvmYW5SFO6pXYdvhBObIlUE8q3sYXacAS0b2Te5a_BrgWsLFT3wI7MazUFeiE\/s1600\/Screenshot%25202026-06-19%2520180642%2520%25281%2529.webp?ssl=1\" alt=\"The Wordfence firewall detects the path traversal attempt in form data and blocks the request ( source : wordfence)\"><figcaption class=\"wp-element-caption\">The Wordfence firewall detects the path traversal attempt in form data and blocks the request ( source: Wordfence)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Due to missing validation checks, the plugin processes this input during its automated privacy cleanup routine. The system then deletes the targeted file using <a href=\"https:\/\/cybersecuritynews.com\/20000-wordpress-sites-vulnerable-to-arbitrary-file-upload\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress\u2019s native file deletion<\/a> function.<\/p>\n<p class=\"wp-block-paragraph\">Notably, the attacker can trigger this cleanup process immediately by controlling specific form parameters, requiring no authentication or administrator interaction.<\/p>\n<p class=\"wp-block-paragraph\">Deleting critical files, such as\u00a0wp-config.php, forces WordPress into a setup state. This can allow attackers to reconfigure the site using a malicious database, ultimately leading to full site takeover and remote code execution.<\/p>\n<p class=\"wp-block-paragraph\">Given the plugin\u2019s popularity and the ease with which it can be exploited, this vulnerability poses a significant risk to affected websites.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/06\/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">vulnerability was reported through Wordfence <\/a>on May 13, 2026, validated and disclosed to the vendor on May 15, and patched by the Avada team on May 19. The fix was officially released in Avada version 3.15.4 on June 2, 2026.<\/p>\n<p class=\"wp-block-paragraph\">Users are strongly advised to update to Avada Builder version 3.15.4 immediately. Websites running outdated versions remain vulnerable to active exploitation.<\/p>\n<p class=\"wp-block-paragraph\">Wordfence users are protected against this attack through built-in firewall rules that detect and block path traversal attempts in form submissions. The root cause lies in the plugin\u2019s failure to enforce directory containment checks or resolve file paths securely.<\/p>\n<p class=\"wp-block-paragraph\">Without validating the final resolved path, the system allows traversal sequences to escape the intended directory, enabling arbitrary file deletion.<\/p>\n<p class=\"wp-block-paragraph\">This case highlights the ongoing risks of insufficient input validation in file-handling functions. It reinforces the importance of secure coding practices in plugin development.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/avada-wordpress-plugin-vulnerability\/\">Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/avada-wordpress-plugin-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648,593],"tags":[130],"class_list":["post-13754","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","category-wordpress","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13754"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13754"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13754\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}