Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function. An unauthenticated attacker can delete arbitrary files on the server by manipulating the file_path parameter in the fusion_form_maybe_delete_files AJAX action. Deleting critical files like wp-config.php can lead to complete site takeover via reinstallation. This template detects the vulnerable version via homepage asset URL versioning (primary) and readme.txt Stable tag (fallback). References: https://www.wordfence.com/blog/2026/06/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/ https://nvd.nist.gov/vuln/detail/CVE-2026-8713 Remediation: Upgrade the Avada Builder (Fusion Builder) plugin to version 3.15.4 or later.
Used 3.4k times · domain, subdomain, ipv4