A critical vulnerability in the Avada (Fusion) Builder WordPress plugin, tracked as CVE-2026-8713, allows unauthenticated attackers to delete arbitrary files on affected sites and potentially seize control of them. The flaw, rated CVSS 9.1, affects all versions through 3.15.3 and is caused by insufficient file path validation in the plugin’s maybe_delete_files() function, enabling path traversal through the wp_ajax_nopriv_fusion_form_submit_ajax handler. The issue is especially dangerous on sites with a published Avada form configured to save entries to the database, where a crafted submission can trigger immediate privacy cleanup and remove sensitive files such as wp-config.php.
Security researchers said deleting key WordPress files can force a site back into setup mode, creating a path to full site compromise and possible remote code execution. The bug was reported by researcher daroo through the Wordfence Bug Bounty Program, and ThemeFusion patched it in Avada Builder 3.15.4. The vulnerability impacts a plugin ecosystem used by roughly one million WordPress sites; while there is no confirmed evidence of widespread exploitation, defenders have been urged to update immediately, and Wordfence said its firewall can block exploit attempts by detecting path traversal sequences in submitted form data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researcher "daroo" reported a critical unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder WordPress plugin through the Wordfence Bug Bounty Program, and the vendor acknowledged the issue. The flaw was later tracked as CVE-2026-8713 and affects versions up to and including 3.15.3.
ThemeFusion patched CVE-2026-8713 in Avada Builder version 3.15.4. The fix addressed insufficient file path validation that allowed unauthenticated attackers to use path traversal to delete arbitrary files on vulnerable sites.
Researcher "daroo" submitted the Avada Builder arbitrary file deletion vulnerability to the Wordfence Bug Bounty Program. According to the new reference, Wordfence received the report on May 13, 2026, before later notifying the vendor and public patch release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.