Skip to main content
Mallory
Unrated

Unauthenticated Arbitrary File Deletion in Avada (Fusion) Builder <= 3.15.3

IdentifiersCVE-2026-8713CWE-22

CVE-2026-8713 is a critical arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress affecting all versions up to and including 3.15.3. The flaw is caused by insufficient file path validation in the maybe_delete_files() function, reported as part of the Fusion form handling code path. The vulnerable logic converts a user-influenced upload URL into a local filesystem path and deletes the resulting file without performing adequate canonicalization or containment checks, allowing path traversal sequences to escape the intended upload directory. Exploitation is possible through the unauthenticated wp_ajax_nopriv_fusion_form_submit_ajax handler when a target site exposes a published Avada form configured to save entries to the database. An attacker can submit a crafted form entry containing a traversal payload and manipulate the fusion_privacy_expiration_interval and privacy_expiration_action fields to force immediate cleanup. The malicious entry is then automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine, resulting in deletion of attacker-selected files on the server without administrator interaction.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to delete arbitrary files accessible to the WordPress process. This can cause direct availability impact and can also enable full site compromise. In particular, deletion of critical files such as wp-config.php can force the WordPress instance back into setup mode, creating a path to site takeover, attacker-controlled reconfiguration, installation of malicious code, and eventual remote code execution. The available reporting characterizes the overall impact as potentially complete site compromise affecting confidentiality, integrity, and availability.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by disabling or restricting access to published Avada forms, especially forms configured to save entries to the database. Remove public access to unnecessary form endpoints, monitor for suspicious submissions containing path traversal patterns, and watch for unexpected file deletions or WordPress setup-state resets. Where available, deploy protective controls such as a WAF rule set capable of detecting traversal payloads in Fusion form submissions.

Remediation

Patch, then assume compromise.

Upgrade Avada (Fusion) Builder to version 3.15.4 or later, which contains the vendor patch for CVE-2026-8713. Because the issue is exploitable without authentication, affected installations running 3.15.3 or earlier should be updated immediately. After patching, review the environment for signs of exploitation, including unexpected deletion of files such as wp-config.php, anomalous form submissions, and unauthorized site reconfiguration or plugin/theme changes.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

ACTIVITY FEED

Recent activity

11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Jun 19, 2026
Critical WordPress Plugin Vulnerability Exposes File Deletion 1 Million Sites to File Deletion Attacks

A critical arbitrary file-deletion/path traversal vulnerability in the Avada (Fusion) Builder WordPress plugin that can let unauthenticated attackers delete arbitrary files and potentially achieve full site takeover and remote code execution.

Read more
security online infoNews
Jun 19, 2026
Avada Builder Flaw: File Deletion Hits 1M Sites (9.1)

A critical unauthenticated arbitrary file deletion vulnerability in themefusion Avada (Fusion) Builder that can be leveraged to delete sensitive files such as wp-config.php and potentially lead to full site compromise and remote code execution.

Read more
cvefeed high severityNews
Jun 19, 2026
CVE-2026-8713 - Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value

An unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress that can potentially lead to remote code execution by deleting critical files such as wp-config.php.

Read more
malware newsNews
Jun 18, 2026
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin - Malware News - Malware Analysis, News and Indicators

A critical unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder WordPress plugin caused by insufficient file path validation in maybe_delete_files(), enabling path traversal-based deletion of arbitrary server files and possible site takeover or remote code execution.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity7

Community discussion across Reddit, Mastodon, and other social sources.