Back Scworld Two vulnerabilities found in popular WordPress plugin Avada Builder | brief
Based on information from Tech Radar, two security flaws were discovered in Avada Builder, a widely used WordPress plugin with approximately one million active installations. These vulnerabilities could have potentially allowed unauthorized access to sensitive user data.
Patches for these issues were released by the developers in April and May 2026, with users strongly advised to update to version 3.15.3 or later. The researcher who discovered these flaws, Rafie Muhammad, was awarded a bounty of around $4,500 through the Wordfence Bug Bounty Program.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
