CVE-2026-8713 is a critical arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress affecting all versions up to and including 3.15.3. The flaw is caused by insufficient file path validation in the maybe_delete_files() function in the Fusion_Form_DB_Entries class. The vulnerable code converts a submitted upload URL into a filesystem path and deletes the resulting file without securely resolving the path or enforcing containment within the intended upload directory. Because traversal sequences are not neutralized, an unauthenticated attacker can supply a crafted path that escapes the expected directory and causes deletion of arbitrary files on the server. The vulnerable execution path is reachable through unauthenticated form submission handling and subsequent automated privacy-cleanup processing of stored form entries. Deletion of critical WordPress files can place the site into a reinstallation state and create a path to full site compromise and eventual remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone Python exploit/scan tool for CVE-2026-8713 affecting ThemeFusion Fusion Builder/Avada WordPress deployments. Structure is minimal: one main Python script (cve_2026_8713.py), a README describing the vulnerability and usage, and a requirements file for requests/urllib3. The script is not part of a larger exploitation framework. Core capability: it detects Avada/Fusion Builder installations, extracts version hints, locates public Avada forms, and abuses the unauthenticated fusion_form_submit_ajax workflow at /wp-admin/admin-ajax.php to submit path traversal values intended for later deletion by the vulnerable privacy cleanup logic. Detection mode appears to assess exposure without destructive action; exploit mode sends deletion payloads targeting wp-config.php by default, with optional custom traversal paths. The exploit logic fingerprints targets by requesting known plugin/theme files such as /wp-content/plugins/fusion-builder/fusion-builder.php and /wp-content/themes/Avada/style.css, then attempts version extraction from /wp-content/plugins/fusion-builder/readme.txt or theme CSS headers. The README and visible code indicate support for both POST and GET requests to the AJAX endpoint, explicitly using GET as a WAF bypass when POST is blocked. Payload intent is destructive rather than shell-dropping: delete critical files to create follow-on compromise conditions. The primary target is ../../wp-config.php, which the repository states forces WordPress into install mode and enables attacker-controlled reconfiguration leading to RCE. Additional hardcoded targets include .htaccess, Wordfence plugin files, and debug logs. The script also contains verification paths to check whether deletion likely succeeded. Operationally, the tool supports single-target and mass-target scanning, multithreading, verbose output, optional result saving, and custom deletion paths. Based on the repository contents, this is a real exploit with both reconnaissance and exploitation functionality, and its maturity is best classified as OPERATIONAL because it includes working exploit delivery and hardcoded destructive payloads, but is not embedded in a broader customizable framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder WordPress plugin caused by path traversal in the maybe_delete_files() function, which can allow deletion of sensitive files such as wp-config.php and potentially lead to full administrative control/RCE.
A critical file deletion vulnerability affecting the Avada Builder WordPress plugin.
A critical arbitrary file-deletion/path traversal vulnerability in the Avada (Fusion) Builder WordPress plugin that can let unauthenticated attackers delete arbitrary files and potentially achieve full site takeover and remote code execution.
A critical unauthenticated arbitrary file deletion vulnerability in themefusion Avada (Fusion) Builder that can be leveraged to delete sensitive files such as wp-config.php and potentially lead to full site compromise and remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.