---
title: "Avada Builder WordPress plugin flaws allow site credential theft"
url: https://daily.dev/posts/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft-k2nrzqgnw
source_url: https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft
type: article
source: "BleepingComputer"
published: 2026-05-15T16:01:58.532Z
updated: 2026-08-24T07:04:12.583Z
tags: ["sql", "wordpress", "web-security"]
reading_time: 3
upvotes: 1
comments: 1
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Avada Builder WordPress plugin flaws allow site credential theft

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 1 comments

## Summary

Two security vulnerabilities have been discovered in the Avada Builder WordPress plugin, which has approximately one million active installations. CVE-2026-4782 is an arbitrary file read flaw exploitable by authenticated users with subscriber-level access, allowing them to read sensitive files like wp-config.php containing database credentials. CVE-2026-4798 is an unauthenticated time-based blind SQL injection affecting sites that previously used WooCommerce, enabling extraction of password hashes from the database. Both were reported via the Wordfence Bug Bounty Program. A full patch is available in version 3.15.3, released May 12, and site owners are urged to update immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft>

## Community discussion

Top comments from developers on daily.dev.

**@shahbaz7** · 0 upvotes

> This kind of news hits differently when you manage a lot of WordPress client sites using the same stack.
>
> We use Avada Builder across quite a few projects, so the worrying part here is not just the vulnerability itself, it’s the scale. The moment a widely used plugin gets exposed, it becomes a huge attack surface overnight.
>
> What people also underestimate is the operational side of this. Suddenly you’re auditing installs, checking versions, testing updates, reviewing backups, and making sure client sites are not exposed. Across multiple sites, that becomes messy very quickly.
>
> At the same...

## Similar posts on daily.dev

- [Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin](https://daily.dev/posts/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin-4vu35e6v7) · BleepingComputer · 1 upvotes · 0 comments
- [Critical Avada WordPress theme flaw enables zero-click RCE](https://daily.dev/posts/critical-avada-wordpress-theme-flaw-enables-zero-click-rce-jpzo0b0ao) · BleepingComputer · 0 upvotes · 0 comments
- [Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites](https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn) · The Next Web · 0 upvotes · 0 comments
- [I went for coffee and came back with 6 vulnerabilities in WordPress plugins](https://daily.dev/posts/i-went-for-coffee-and-came-back-with-6-vulnerabilities-in-wordpress-plugins-7fynbiud7) · InfoSec Write-ups · 0 upvotes · 0 comments
- [Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin](https://daily.dev/posts/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin-tcgzmougc) · BleepingComputer · 2 upvotes · 0 comments

---

Tags: [#sql](https://daily.dev/tags/sql), [#wordpress](https://daily.dev/tags/wordpress), [#web-security](https://daily.dev/tags/web-security)

[View this post on daily.dev](https://daily.dev/posts/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft-k2nrzqgnw)
