Teegra 🧝♀️𝕏[verified]@TeeegraDisclosure
Two critical vulnerabilities were disclosed in the Avada Builder plugin: one allowing authenticated subscribers to read any file on the server, and another enabling unauthenticated blind SQL injection. No exploitation code, active attacks, or patches are presented.
kokumօtօ[verified]@__kokumotoPatch
The WordPress Avada Builder plugin has received patches that address two newly disclosed vulnerabilities: an unauthenticated SQL injection (CVE‑2026‑4798) and an arbitrary file read via subscriber permissions (CVE‑2026‑4782).
DFIR Radar[verified]@DFIR_RadarPatch
The post highlights critical vulnerabilities in Avada Builder and urges users to apply the version 3.15.3 patch to mitigate the risks.
Cyber News Live[verified]@cybernewslivePatch
The article discloses two serious CVEs in the Avada Builder plugin that allow file and database read access, and it instructs users to update to version 3.15.3 to remediate the flaws.
Echo Horizon[verified]@Echo_Horizon139Disclosure
New critical vulnerabilities (CVE‑2026‑4782 and CVE‑2026‑4798) in the Avada Builder plugin expose arbitrary file read and SQL injection risks, potentially allowing unauthenticated attackers to access sensitive data. A patch is available—users should update to Avada Builder v3.15.3 immediately.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The analysis confirms that attackers have actively exploited two Avada Builder vulnerabilities—SQL injection (CVE-2026-4798) and arbitrary file read (CVE-2026-4782)—to compromise more than 1 million WordPress sites.
iototsecnews@iototsecnewsDisclosure
The post announces disclosures of two Avada Builder vulnerabilities (CVE‑2026‑4782 and CVE‑2026‑4798), explains their technical causes and potential impact on up to one million WordPress sites, but does not provide PoC, exploit code, evidence of active exploitation, or specific remediation details.
ASTRAL@MeAstraLDisclosure
CVE-2026-4782 exposes arbitrary file read and SQL injection flaws in AvadaBuilder plugin (versions <=3.15.2), affecting roughly 1,000,000 WordPress sites. A patched version 3.15.3 is available.