Bleepingcomputer Critical Vulnerabilities in Avada Builder Plugin Expose WordPress Sites to Credential Theft
Article Content
- •Two critical vulnerabilities in the Avada Builder plugin could lead to credential theft.
- •CVE-2026-4798 allows SQL injection attacks without authentication under specific conditions.
- •Affected users are advised to update to version 3.15.3 to protect against these vulnerabilities.
Two vulnerabilities in the Avada Builder plugin for WordPress, affecting approximately one million installations, allow unauthorized access to sensitive data. The first vulnerability enables hackers to read arbitrary files, including wp-config.php, which contains critical database credentials. The second, an SQL injection flaw (CVE-2026-4798), can be exploited by unauthenticated attackers to extract sensitive information from the database, provided the WooCommerce plugin was previously used. These issues were reported by researcher Rafie Muhammad, who received a total bounty of $4,453. A partial fix was released on April 13, 2026, and a complete patch on May 12, 2026. Website administrators are urged to update to version 3.15.3 immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Avada and CVE-2026-4798 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…