CVE-2026-4798Disclosure

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if WooCommerce was previously used and then deactivated.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 14 signals
  • Disclosure: 7 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-15); latest day: 1
  • 14 total mentions across 8 days

Deep dive

Activity timeline14 mentions / 8d
01223Mentions · 2026-05-12: 2Mentions · 2026-05-13: 2Mentions · 2026-05-15: 3Mentions · 2026-05-16: 1Mentions · 2026-05-18: 3Mentions · 2026-05-20: 1Mentions · 2026-05-25: 1Mentions · 2026-06-18: 1Active Exploitation · 2026-05-16: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 3Technical Details · 2026-05-20: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-18: 105-1205-1305-1505-1605-1805-2005-2506-18
Signal classification3 categories
Disclosure
750.0%
Patch
642.9%
Active Exploitation
17.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure1Patch1
2026-05-132
Disclosure1Patch1
2026-05-153
Disclosure2Patch1
2026-05-161
Active Exploitation1
2026-05-183
Disclosure2Patch1
2026-05-201
Patch1
2026-05-251
Patch1
2026-06-181
Disclosure1
Full discourse14 posts
  • Teegra 🧝‍♀️𝕏@Teeegra
    Disclosure

    دو آسیب‌پذیری خطرناک در افزونه پرکاربرد وردپرس «Avada Builder» با بیش از یک میلیون نصب فعال کشف شده که به هکرها امکان می‌دهد فایل‌های دلخواه را بخوانند و اطلاعات حساس را از پایگاه داده استخراج کنند. اولین آسیب‌پذیری با شناسه CVE-2026-4782، در تمام نسخه‌های تا 3.15.2 وجود دارد و به کاربران احراز هویت‌شده با حداقل سطح دسترسی «مشترک» (subscriber) اجازه می‌دهد محتوای هر فایلی روی سرور، از جمله فایل حساس wp-config.php حاوی اعتبارنامه‌های پایگاه داده و کلیدهای رمزنگاری، را بخوانند که می‌تواند به تصاحب کامل سایت منجر شود. آسیب‌پذیری دوم با شناسه CVE-2026-4798، یک حمله تزریق SQL (SQL injection) کور مبتنی بر زمان است که نسخه‌های تا 3.15.1 را تحت تأثیر قرار می‌دهد و بدون نیاز به احراز هویت قابل بهره‌برداری است، مشروط بر اینکه افزونه WooCommerce پیش‌تر فعال و سپس غیرفعال شده باشد.

    Post summary

    Two newly disclosed vulnerabilities in Avada Builder (CVE-2026-4782 and CVE-2026-4798) allow unauthorized file reading and blind SQL injection, posing serious risk to WordPress sites.

    00095897
    19.1K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress Plugin https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/ @wordfenceより CVE-2026-4798 Avada Builder <= 3.15.1 - 'product_order' パラメータを介した認証不要の SQL インジェクション

    Post summary

    The post discloses that Avada Builder plugins up to version 3.15.1 have an unauthenticated SQL injection vulnerability via the 'product_order' parameter, potentially affecting 1,000,000+ WordPress sites.

    00022827
    11.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    百万サイト以上が使用するWordPressのAvada Builderで、無認証SQLインジェクションの脆弱性(CVE-2026-4798)と購読者権限からの任意ファイル読み取りの脆弱性(CVE-2026-4782)が修正。 https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/

    Post summary

    An update has been released for Avada Builder, fixing CVE‑2026‑4798 (unauthenticated SQL injection) and CVE‑2026‑4782 (arbitrary file read from subscriber role). These patches mitigate the identified vulnerabilities.

    00012809
    7.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Critical flaws in Avada Builder plugin (1M+ installs) allow unauthenticated SQL injection (CVE-2026-4798, CVSS 7.5) and authenticated file read (CVE-2026-4782, CVSS 6.5). Update to version 3.15.3 immediately. #DFIR_Radar https://t.co/hlIx3Bt9aY

    Post summary

    The tweet warns of critical SQL injection and file read flaws in Avada Builder and urges users to update to version 3.15.3.

    1001091
    1.5K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-4798: high severity (CVSS 7.5). Avada Builder plugin for WordPress has a SQL injection issue worth scoping now. Do the unglamorous work early. It compounds.

    Post summary

    The post announces CVE‑2026‑4798, a high‑severity SQL injection vulnerability in the Avada Builder WordPress plugin, with a CVSS score of 7.5 and no indication of active exploitation or fixes.

    1000049
    337 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress Avada プラグインの脆弱性 CVE-2026-4782/4798 が FIX:100万件のサイトが危険な状態 https://iototsecnews.jp/2026/05/13/avada-builder-flaws-expose-one-million-wordpress-sites/ 脆弱性 CVE-2026-4782 の原因は、外部から指定されたファイルの種類や参照元を検証する処理が不足し、機密情報が読み取れる状態になっていたことにあります。また、脆弱性 CVE-2026-4798 は、入力値のサニタイズが不十分であったことに加え、データベースへの命令文を組み立てる際に、エスケープ処理を行わずに連結していたことが原因です。これらは基本的な処理の不足から生じるものですが、結果として多くのサイトに影響を与える問題に繋がりました。開発においては、外部からの入力値をそのまま信頼せず、標準的な関数を組み合わせて安全に処理を完結させることが重要となります。利用のチームは、ご注意ください。 #Avada #CVE20264782 #CVE20264798 #Vulnerability #WordPress

    Post summary

    The post reports that two CVEs (CVE‑2026‑4782 and CVE‑2026‑4798) affect about one million WordPress sites via the Avada Builder plugin, details missing input validation and escaping, and indicates a patch is available.

    01000154
    489 followersView on X
  • Cyber News Live@cybernewslive
    Disclosure

    Two security flaws in the Avada Builder plugin — installed on roughly one million WordPress websites — let attackers read sensitive server files and extract database contents including password hashes. The first flaw (CVE-2026-4782) lets any logged-in user, even a basic subscriber, read the site's configuration file, which contains database credentials and encryption keys — enough to take over the entire site. The second flaw (CVE-2026-4798) requires no login at all and can pull password hashes directly from the database, but only on sites that previously used WooCommerce and then deactivated it. Both flaws are fixed in Avada Builder version 3.15.3 — if your website runs this plugin, update it now. Open your WordPress dashboard, go to Plugins → Installed Plugins, find Avada Builder, and update to version 3.15.3. 🔥 #CyberNewsLive https://bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/

    Post summary

    The article discloses two CVEs in Avada Builder that let attackers read server files and fetch password hashes, and urges users to upgrade to the patched 3.15.3 version.

    00001120
    2.1K followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress Avada の脆弱性 CVE-2026-4782/4798 が FIX:任意のファイル読み取りと SQLi の恐れ https://iototsecnews.jp/2026/05/18/1-million-wordpress-websites-exposed-by-avada-builder-security-vulnerabilities/ WordPress プラグイン Avada Builder に見つかった、2 種類の深刻な脆弱性を解説する記事です。問題の原因は、 画像表示関数におけるファイル形式や取得元の検証不備の CVE-2026-4782 と、データベース処理時におけるクエリのパラメータ化の欠落の CVE-2026-4798 にあります。これらが原因で、低権限のユーザーによる重要ファイル “wp-config.php” の読み取りや、未認証の攻撃者による不正な SQL 命令の送り込みが発生します。放置するとサイト全体の乗っ取りに繋がるため、管理者は直ちに完全修正版であるバージョン 3.15.3 へ更新する必要があります。 #AvadaBuilder #CVE20264782 #CVE20264798 #Vulnerability #WordPress

    Post summary

    The post outlines two critical CVEs in the Avada Builder plugin that enable unauthenticated file reading and SQL injection, and it urges admins to apply version 3.15.3 immediately to mitigate the risks.

    00000107
    490 followersView on X
  • JNR Management@jnrmanagement
    Disclosure

    🚨 One Million WordPress Sites at Risk — Avada Builder's CVE-2026-4782 File Read and CVE-2026-4798 SQL Injection Flaws Demand Immediate Update to 3.15.3. 👉 Read More: https://www.jnrmanagement.com/avada-builder-flaws-expose-1-million-wordpress-sites-to-file-read-and-sql-injection.html #CyberSecurity #JNRManagement #CISO #WordPress #AvadaBuilder #SQLInjection https://t.co/SMb4DkKNMy

    Post summary

    The post announces that Avada Builder's CVE-2026-4782 File Read and CVE-2026-4798 SQL Injection flaws affect about a million WordPress sites, urging users to update to version 3.15.3.

    0000053
    177 followersView on X
  • Echo Horizon@Echo_Horizon139
    Patch

    Over 𝟭𝗠𝗜𝗟𝗟𝗜𝗢𝗡 𝗪𝗼𝗿𝗱𝗣𝗿𝗲𝘀𝘀 websites are at risk after critical vulnerabilities were discovered in the 𝗔𝘃𝗮𝗱𝗮 𝗕𝘂𝗶𝗹𝗱𝗲𝗿 𝗽𝗹𝘂𝗴𝗶𝗻 Attackers can exploit ⚠️ Arbitrary File Read (CVE-2026-4782) ⚠️ SQL Injection (CVE-2026-4798) The flaws could expose sensitive data, including password hashes and server configuration files. One vulnerability can even be exploited without authentication under specific conditions. Users are strongly advised to update to 𝗔𝘃𝗮𝗱𝗮 𝗕𝘂𝗶𝗹𝗱𝗲𝗿 𝘃𝟯.𝟭𝟱.𝟯 immediately before threat actors begin mass exploitation campaigns. 🔗 https://cybersecuritynews.com/avada-builder-plugin-vulnerability/ 👉 𝗙𝗼𝗹𝗹𝗼𝘄 𝗳𝗼𝗿 𝗿𝗲𝗮𝗹-𝘁𝗶𝗺𝗲 𝗰𝘆𝗯𝗲𝗿 𝘁𝗵𝗿𝗲𝗮𝘁 𝗮𝗹𝗲𝗿𝘁𝘀 #WordPress #CyberSecurity #Infosec #CVE #WebSecurity #SQLInjection

    Post summary

    The article highlights critical vulnerabilities in the Avada Builder plugin—enabling arbitrary file read and SQL injection—emphasizes the need for an immediate patch to v3.15.3, and does not report ongoing exploitation.

    00000134
    144 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chained two Avada Builder vulnerabilities to achieve full WordPress site compromise across 1M+ installations. SQL injection (CVE-2026-4798) enabled database extraction, followed by arbitrary file reads (CVE-2026-4782) to access wp-config credentials. Runtime segmentation helps contain such multi-stage attack chains. #Vulnerability #WebSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft-cve-2026-4782-cve-2026-4798

    Post summary

    A TRC analysis reports attackers chained CVE‑2026‑4798 (SQL injection) and CVE‑2026‑4782 (arbitrary file reads) to fully compromise WordPress sites, with evidence of real‑world use across over one million installations.

    0000056
    1.9K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical flaws in Avada Builder WordPress plugin expose 1M sites to file read and CVE-2026-4798 SQL injection, admins urged to update to version 3.15.3 now. https://threatcluster.io/cluster/critical-vulnerabilities-in-avada-builder-plugin-expose-word-7bbc2d99

    Post summary

    The post announces critical file read and SQL injection vulnerabilities in Avada Builder, urges users to apply the 3.15.3 patch, and highlights the need for immediate updates.

    0000075
    277 followersView on X
  • Mark McNeece@bsolveit
    Disclosure

    1M Avada sites "at risk" from CVE-2026-4798. Buried fact nobody covered: the SQL injection only fires on sites with a deactivated WooCommerce. That changes everything. https://www.365i.co.uk/news/2026/05/15/avada-builder-sql-injection-cve-2026-4798/ #WordPress #WPSecurity #Avada #CVE

    Post summary

    The notice announces a SQL injection flaw in Avada Builder (CVE-2026-4798) that threatens about 1 million WordPress sites, specifically affecting those with WooCommerce deactivated, but offers no patch or exploitation details.

    0000053
    189 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4798 SQL Injection in Avada Builder Plugin for WordPress Versions Up to 3.15.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4798

    Post summary

    The post announces CVE-2026-4798 as an SQL injection flaw in Avada Builder Plugin up to version 3.15.1, but provides no PoC, exploit details, or mitigation information.

    0000053
    4.0K followersView on X

Explore more