A critical unauthenticated arbitrary file deletion vulnerability, tracked as CVE-2026-8713, was disclosed in the Avada (Fusion) Builder plugin for WordPress. The flaw affects versions through 3.15.3 and stems from insufficient validation of the file_path parameter in the maybe_delete_files() function within the Fusion_Form_DB_Entries class, enabling directory traversal and deletion of arbitrary files on the server.
Researchers warned that attackers could delete sensitive files such as wp-config.php, potentially forcing a WordPress site into a reinstallation state and allowing an adversary to seize administrative control and possibly achieve remote code execution. Wordfence reported that a patch has been released, and the security community has already published a Nuclei detection template to help defenders identify exposed installations and prioritize remediation.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A pull request was opened in the ProjectDiscovery nuclei-templates repository to add detection coverage for CVE-2026-8713, the Avada Builder arbitrary file deletion vulnerability. The template references NVD, Wordfence, and Falcon Internet for the vulnerability details.
Wordfence reported that a critical unauthenticated arbitrary file deletion vulnerability affecting the Avada (Fusion) Builder WordPress plugin was patched. The issue affects versions up to 3.15.3 and could allow deletion of files such as wp-config.php, potentially enabling site takeover and remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.