Skip to content

Known CVE

Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function. An unauthenticated attacker can delete arbitrary files on the server by manipulating the file_path parameter in the fusion_form_maybe_delete_files AJAX action. Deleting critical files like wp-config.php can lead to complete site takeover via reinstallation. This template detects the vulnerable version via homepage asset URL versioning (primary) and readme.txt Stable tag (fallback).

CVE-2026-8713

Critical2026CVSS 9.1CWE-22

cve2026 · wordpress · wp-plugin · avada · fusion-builder · file-deletion · passive · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website