Skip to content
Two vulnerabilities found in popular WordPress plugin Avada Builder | brief

Two vulnerabilities found in popular WordPress plugin Avada Builder | brief

Scworld May 14, 2026

Based on information from Tech Radar, two security flaws were discovered in Avada Builder, a widely used WordPress plugin with approximately one million active installations. These vulnerabilities could have potentially allowed unauthorized access to sensitive user data.

Patches for these issues were released by the developers in April and May 2026, with users strongly advised to update to version 3.15.3 or later. The researcher who discovered these flaws, Rafie Muhammad, was awarded a bounty of around $4,500 through the Wordfence Bug Bounty Program.

Extracted Entities