One of the most popular plugins in the WordPress ecosystem is at the center of controversy after two critical vulnerabilities that could allow attackers to gain access to sensitive data and server files. The problem concerns Avada Builder, a plugin used on more than a million websites worldwide and considered an essential tool for creating and managing WordPress websites.

Security researchers warn that these vulnerabilities may be actively exploited by cybercriminals, especially on websites that have not installed the latest security updates.
The vulnerabilities were discovered by security researcher Rafie Muhammad through the Wordfence Bug Bounty program and have been recorded as CVE-2026-4782 and CVE-2026-4798.
See also: DirtyDecrypt: PoC exploit released for Linux vulnerability
The first security flaw allows access to critical files
The first vulnerability concerns an arbitrary file reading and affects Avada Builder versions up to 3.15.2. This flaw allows even low-privilege users, such as simple subscribers, to gain access to sensitive files on the server.
The issue lies in the way the plugin handles the custom_svg through shortcode functions. Due to incomplete input validation, attackers can manipulate the file upload process and retrieve content from arbitrary locations within the system.
This means that files that are particularly critical to the security of a WordPress site, such as wp-config.php, can be exposed. This file contains database login details, authentication keys, and other sensitive credentials that can lead to a complete breach of the website.
Although the vulnerability's CVSS score is 6.5 and is classified as "moderate severity", experts point out that the actual risk is much greater, as the exploit requires minimal access rights.

SQL Injection vulnerability is considered even more dangerous
The second vulnerability, codenamed CVE-2026-4798, is considered significantly more serious and has received a CVSS score of 7.5. It is an SQL injection vulnerability that allows unauthorized attackers to execute malicious queries on the database.
See also: Claw Chain: OpenClaw vulnerabilities allow complete system compromise
The problem is located in the product_order, where the plugin fails to properly sanitize SQL queries before they are executed in the database.
Through time-based SQL injection techniques, attackers can extract data gradually, without causing obvious error messages or suspicious activity that would be easily noticed by administrators.
Cybercriminals can leverage SQL functions like SLEEP() to verify whether injected commands are executed successfully and extract information step by step. This way, it is possible to obtain usernames, password hashes, user emails, and other critical data stored in the WordPress database.
Although the attack requires a specific condition — WooCommerce being previously installed and later disabled — experts point out that many websites unwittingly fulfill this scenario.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Why WordPress plugins are a huge target for hackers
The incident brings to the fore a perennial problem in the WordPress ecosystem: third-party plugins constitute one of the largest attack surfaces on the modern web.
The more popular a plugin is, the more attractive the target becomes for cybercriminal groups. A successful exploit on a plugin with over a million installations can lead to massive automated attacks within hours.
In recent years, attackers have been using bots that scan the internet looking for websites with outdated plugin versions. Once a vulnerable site is identified, the exploit is carried out automatically, without any human intervention.
See also: MiniPlasma: New Windows zero-day worries admins
This means that even small businesses or personal blogs can be targeted within a short time of a new vulnerability being made public.

Avada Builder: Security updates are now a must
The Avada Builder development team released fix updates in two stages, with the full fix being completed in version 3.15.3, which was released on May 12, 2026.
Security experts recommend immediately upgrading to the latest available version, as well as checking user accounts for unnecessary subscriber accounts that could be exploited by attackers.
At the same time, it is recommended to use a Web Application Firewall such as Wordfence, monitor suspicious database queries , and regularly check server logs for unusual file access.
The incident is yet another reminder that even the most trusted plugins can become a serious security risk when not updated in a timely manner. In today’s world of automated cyberattacks, the speed of installing security patches remains the most effective defense for any WordPress site.
