CVE-2026-4782Patch

MEDIUMCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability was partially patched in version 3.15.2 and fully patched in version 3.15.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-36

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-13); latest day: 1
  • 11 total mentions across 7 days

Deep dive

Activity timeline11 mentions / 7d
01223Mentions · 2026-05-12: 1Mentions · 2026-05-13: 3Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-18: 3Mentions · 2026-05-20: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-16: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 3Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 3Technical Details · 2026-05-20: 1Technical Details · 2026-05-25: 105-1205-1305-1505-1605-1805-2005-25
Signal classification3 categories
Patch
545.5%
Disclosure
545.5%
Active Exploitation
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-133
Disclosure2Patch1
2026-05-151
Patch1
2026-05-161
Active Exploitation1
2026-05-183
Disclosure2Patch1
2026-05-201
Disclosure1
2026-05-251
Patch1
Full discourse11 posts
  • Teegra 🧝‍♀️𝕏@Teeegra
    Disclosure

    دو آسیب‌پذیری خطرناک در افزونه پرکاربرد وردپرس «Avada Builder» با بیش از یک میلیون نصب فعال کشف شده که به هکرها امکان می‌دهد فایل‌های دلخواه را بخوانند و اطلاعات حساس را از پایگاه داده استخراج کنند. اولین آسیب‌پذیری با شناسه CVE-2026-4782، در تمام نسخه‌های تا 3.15.2 وجود دارد و به کاربران احراز هویت‌شده با حداقل سطح دسترسی «مشترک» (subscriber) اجازه می‌دهد محتوای هر فایلی روی سرور، از جمله فایل حساس wp-config.php حاوی اعتبارنامه‌های پایگاه داده و کلیدهای رمزنگاری، را بخوانند که می‌تواند به تصاحب کامل سایت منجر شود. آسیب‌پذیری دوم با شناسه CVE-2026-4798، یک حمله تزریق SQL (SQL injection) کور مبتنی بر زمان است که نسخه‌های تا 3.15.1 را تحت تأثیر قرار می‌دهد و بدون نیاز به احراز هویت قابل بهره‌برداری است، مشروط بر اینکه افزونه WooCommerce پیش‌تر فعال و سپس غیرفعال شده باشد.

    Post summary

    Two critical vulnerabilities were disclosed in the Avada Builder plugin: one allowing authenticated subscribers to read any file on the server, and another enabling unauthenticated blind SQL injection. No exploitation code, active attacks, or patches are presented.

    00095897
    19.1K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    百万サイト以上が使用するWordPressのAvada Builderで、無認証SQLインジェクションの脆弱性(CVE-2026-4798)と購読者権限からの任意ファイル読み取りの脆弱性(CVE-2026-4782)が修正。 https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/

    Post summary

    The WordPress Avada Builder plugin has received patches that address two newly disclosed vulnerabilities: an unauthenticated SQL injection (CVE‑2026‑4798) and an arbitrary file read via subscriber permissions (CVE‑2026‑4782).

    00012809
    7.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Critical flaws in Avada Builder plugin (1M+ installs) allow unauthenticated SQL injection (CVE-2026-4798, CVSS 7.5) and authenticated file read (CVE-2026-4782, CVSS 6.5). Update to version 3.15.3 immediately. #DFIR_Radar https://t.co/hlIx3Bt9aY

    Post summary

    The post highlights critical vulnerabilities in Avada Builder and urges users to apply the version 3.15.3 patch to mitigate the risks.

    1001091
    1.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Avada プラグインの脆弱性 CVE-2026-4782/4798 が FIX:100万件のサイトが危険な状態 https://iototsecnews.jp/2026/05/13/avada-builder-flaws-expose-one-million-wordpress-sites/ 脆弱性 CVE-2026-4782 の原因は、外部から指定されたファイルの種類や参照元を検証する処理が不足し、機密情報が読み取れる状態になっていたことにあります。また、脆弱性 CVE-2026-4798 は、入力値のサニタイズが不十分であったことに加え、データベースへの命令文を組み立てる際に、エスケープ処理を行わずに連結していたことが原因です。これらは基本的な処理の不足から生じるものですが、結果として多くのサイトに影響を与える問題に繋がりました。開発においては、外部からの入力値をそのまま信頼せず、標準的な関数を組み合わせて安全に処理を完結させることが重要となります。利用のチームは、ご注意ください。 #Avada #CVE20264782 #CVE20264798 #Vulnerability #WordPress

    Post summary

    The post announces disclosures of two Avada Builder vulnerabilities (CVE‑2026‑4782 and CVE‑2026‑4798), explains their technical causes and potential impact on up to one million WordPress sites, but does not provide PoC, exploit code, evidence of active exploitation, or specific remediation details.

    01000154
    489 followersView on X
  • Cyber News Live@cybernewslive
    Patch

    Two security flaws in the Avada Builder plugin — installed on roughly one million WordPress websites — let attackers read sensitive server files and extract database contents including password hashes. The first flaw (CVE-2026-4782) lets any logged-in user, even a basic subscriber, read the site's configuration file, which contains database credentials and encryption keys — enough to take over the entire site. The second flaw (CVE-2026-4798) requires no login at all and can pull password hashes directly from the database, but only on sites that previously used WooCommerce and then deactivated it. Both flaws are fixed in Avada Builder version 3.15.3 — if your website runs this plugin, update it now. Open your WordPress dashboard, go to Plugins → Installed Plugins, find Avada Builder, and update to version 3.15.3. 🔥 #CyberNewsLive https://bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/

    Post summary

    The article discloses two serious CVEs in the Avada Builder plugin that allow file and database read access, and it instructs users to update to version 3.15.3 to remediate the flaws.

    00001120
    2.1K followersView on X
  • ASTRAL@MeAstraL
    Disclosure

    1,000,000 #WordPress Sites Affected by Arbitrary File Read and #SQLInjection Vulnerabilities in #AvadaBuilder WordPress Plugin #⃣CVSS Rating : 6.5 (Medium) 🆔CVE-ID : CVE-2026-4782 🎯Affected Version(s) : <= 3.15.2 ✅Patched Version : 3.15.3

    Post summary

    CVE-2026-4782 exposes arbitrary file read and SQL injection flaws in AvadaBuilder plugin (versions <=3.15.2), affecting roughly 1,000,000 WordPress sites. A patched version 3.15.3 is available.

    00100101
    367 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress Avada の脆弱性 CVE-2026-4782/4798 が FIX:任意のファイル読み取りと SQLi の恐れ https://iototsecnews.jp/2026/05/18/1-million-wordpress-websites-exposed-by-avada-builder-security-vulnerabilities/ WordPress プラグイン Avada Builder に見つかった、2 種類の深刻な脆弱性を解説する記事です。問題の原因は、 画像表示関数におけるファイル形式や取得元の検証不備の CVE-2026-4782 と、データベース処理時におけるクエリのパラメータ化の欠落の CVE-2026-4798 にあります。これらが原因で、低権限のユーザーによる重要ファイル “wp-config.php” の読み取りや、未認証の攻撃者による不正な SQL 命令の送り込みが発生します。放置するとサイト全体の乗っ取りに繋がるため、管理者は直ちに完全修正版であるバージョン 3.15.3 へ更新する必要があります。 #AvadaBuilder #CVE20264782 #CVE20264798 #Vulnerability #WordPress

    Post summary

    The post details two critical Avada Builder vulnerabilities that enable arbitrary file reading and SQL injection, and it urges users to update to v3.15.3 to remediate the risks.

    00000107
    490 followersView on X
  • JNR Management@jnrmanagement
    Patch

    🚨 One Million WordPress Sites at Risk — Avada Builder's CVE-2026-4782 File Read and CVE-2026-4798 SQL Injection Flaws Demand Immediate Update to 3.15.3. 👉 Read More: https://www.jnrmanagement.com/avada-builder-flaws-expose-1-million-wordpress-sites-to-file-read-and-sql-injection.html #CyberSecurity #JNRManagement #CISO #WordPress #AvadaBuilder #SQLInjection https://t.co/SMb4DkKNMy

    Post summary

    The tweet announces newly disclosed vulnerabilities in Avada Builder, emphasizing the need for an immediate patch to version 3.15.3 to mitigate file read and SQL injection flaws.

    0000053
    177 followersView on X
  • Echo Horizon@Echo_Horizon139
    Disclosure

    Over 𝟭𝗠𝗜𝗟𝗟𝗜𝗢𝗡 𝗪𝗼𝗿𝗱𝗣𝗿𝗲𝘀𝘀 websites are at risk after critical vulnerabilities were discovered in the 𝗔𝘃𝗮𝗱𝗮 𝗕𝘂𝗶𝗹𝗱𝗲𝗿 𝗽𝗹𝘂𝗴𝗶𝗻 Attackers can exploit ⚠️ Arbitrary File Read (CVE-2026-4782) ⚠️ SQL Injection (CVE-2026-4798) The flaws could expose sensitive data, including password hashes and server configuration files. One vulnerability can even be exploited without authentication under specific conditions. Users are strongly advised to update to 𝗔𝘃𝗮𝗱𝗮 𝗕𝘂𝗶𝗹𝗱𝗲𝗿 𝘃𝟯.𝟭𝟱.𝟯 immediately before threat actors begin mass exploitation campaigns. 🔗 https://cybersecuritynews.com/avada-builder-plugin-vulnerability/ 👉 𝗙𝗼𝗹𝗹𝗼𝘄 𝗳𝗼𝗿 𝗿𝗲𝗮𝗹-𝘁𝗶𝗺𝗲 𝗰𝘆𝗯𝗲𝗿 𝘁𝗵𝗿𝗲𝗮𝘁 𝗮𝗹𝗲𝗿𝘁𝘀 #WordPress #CyberSecurity #Infosec #CVE #WebSecurity #SQLInjection

    Post summary

    New critical vulnerabilities (CVE‑2026‑4782 and CVE‑2026‑4798) in the Avada Builder plugin expose arbitrary file read and SQL injection risks, potentially allowing unauthenticated attackers to access sensitive data. A patch is available—users should update to Avada Builder v3.15.3 immediately.

    00000134
    144 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chained two Avada Builder vulnerabilities to achieve full WordPress site compromise across 1M+ installations. SQL injection (CVE-2026-4798) enabled database extraction, followed by arbitrary file reads (CVE-2026-4782) to access wp-config credentials. Runtime segmentation helps contain such multi-stage attack chains. #Vulnerability #WebSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft-cve-2026-4782-cve-2026-4798

    Post summary

    The analysis confirms that attackers have actively exploited two Avada Builder vulnerabilities—SQL injection (CVE-2026-4798) and arbitrary file read (CVE-2026-4782)—to compromise more than 1 million WordPress sites.

    0000056
    1.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4782 Arbitrary File Read in Avada Builder Plugin for WordPress Versions Up to 3.15.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4782

    Post summary

    The text provides a disclosure of CVE-2026-4782, describing an arbitrary file read vulnerability in Avada Builder Plugin versions up to 3.15.2.

    0000060
    4.0K followersView on X

Explore more