Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. One of the flaws is tracked as CVE-2026-4782 and can be exploited in all versions of the plugin through 3.15.2 by an authenticated users with at least subscriber-level access to read the contents of any file on the server. The other security issue received the identifier CVE-2026-4798 and is an SQL injection that can be leveraged without authentication. However, exploitation is possible only if the WooCommerce e-commerce plugin for WordPress has been enabled and then deactivated. Avada Builder is a drag-and-drop webpage builder plugin for the Avada WordPress theme that lets you create and customize website layouts, content sections, and design elements without writing code. The two issues were discovered by security researcher Rafie Muhammad, who reported them through the Wordfence Bug Bounty Program and received $3,386 and $1,067, respectively, for the findings. Wordfence explains that the arbitrary file read is possible via the plugin’s shortcode-rendering functionality and the custom_svg parameter. The issue is that the plugin does not properly validate file types or sources, allowing access to sensitive files such as wp-config.php, which typically contains database credentials and cryptographic keys. Access to wp-config.php can lead to the compromise of an administrato...
Avada Builder WordPress plugin flaws allow site credential theft
BleepingComputer
·Bill Toulas
·Published May 15, 2026
·Updated
Affected Software
2 affected components
Avada Builder<=3.15.2
Avada Builder<=3.15.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in the Avada Builder WordPress plugin that can lead to credential theft.
2
What security implications are discussed in this article?
The vulnerabilities allow hackers to read arbitrary files and extract sensitive information from the database.
3
What versions of the Avada Builder plugin are affected?
The affected versions of the Avada Builder plugin include versions up to and including 3.15.2 and 3.15.1.
4
How many active installations of the Avada Builder plugin are there?
The Avada Builder plugin has an estimated one million active installations.
5
Who is the vendor of the Avada Builder plugin?
The Avada Builder plugin is developed by Avada.