Two security vulnerabilities have been discovered in the Avada Builder WordPress plugin, which has approximately one million active installations. CVE-2026-4782 is an arbitrary file read flaw exploitable by authenticated users with subscriber-level access, allowing them to read sensitive files like wp-config.php containing database credentials. CVE-2026-4798 is an unauthenticated time-based blind SQL injection affecting sites that previously used WooCommerce, enabling extraction of password hashes from the database. Both were reported via the Wordfence Bug Bounty Program. A full patch is available in version 3.15.3, released May 12, and site owners are urged to update immediately.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
1.1K Impressions1 Comment