CVE-2026-8713Disclosure

MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

4.3/ 10 priority

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 18 signals
  • Disclosure: 11 classified signals
  • Peaked 9d ago at 6 mentions (2026-06-19); latest day: 1
  • 23 total mentions across 10 days

Deep dive

Activity timeline23 mentions / 10d
02356Mentions · 2026-06-19: 6Mentions · 2026-06-20: 4Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-06-29: 1Mentions · 2026-07-06: 2Mentions · 2026-07-13: 4Mentions · 2026-07-23: 2Mentions · 2026-07-27: 1PoC Mentioned / Linked · 2026-06-21: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-23: 2Exploit Tool / Code · 2026-07-06: 1Patch / Workaround · 2026-06-19: 2Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-13: 2Technical Details · 2026-06-19: 5Technical Details · 2026-06-20: 3Technical Details · 2026-06-21: 1Technical Details · 2026-06-22: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-13: 3Technical Details · 2026-07-27: 106-1906-2006-2106-2206-2306-2907-0607-1307-2307-27
Signal classification4 categories
Disclosure
1147.8%
Patch
730.4%
PoC
313.0%
General
28.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-06-196
Disclosure2General2Patch2
2026-06-204
Disclosure4
2026-06-211
Disclosure1
2026-06-221
Patch1
2026-06-231
Patch1
2026-06-291
Disclosure1
2026-07-062
Patch1PoC1
2026-07-134
Disclosure2Patch2
2026-07-232
PoC2
2026-07-271
Disclosure1
Full discourse20 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-8713 PT ID: PT-2026-50846 Vendor: WordPress / themefusion Product: Avada (Fusion) Builder (WordPress plugin) Description: The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction. Link: https://github.com/shinthink/CVE-2026-8713 #dbugs_vuln

    Post summary

    Proof-of-concept exploit discovered for CVE-2026-8713 affecting AVADA Builder, enabling unauthenticated file deletion that could lead to RCE; PoC code is publicly available on GitHub.

    15041183.5K
    3.4K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-8713: Arbitrary file deletion in Avada Builder WordPress plugin, 9.1 rating 🔥 New vulnerability in Avada Builder WordPress plugin (formerly Fusion Builder) allows an unauthenticated attacker to delete any file on the server. It can easily lead to remote code execution when the right file is deleted. 👉 https://nt.ls/ohFG5

    Post summary

    The post announces a newly disclosed CVE‑2026‑8713 affecting Avada Builder with high severity, detailing the file‑deletion flaw, but offers no proof of concept, exploit code, or remediation information.

    0401031.1K
    7.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    CVE-2026-8713 is a critical Avada Builder vulnerability enabling unauthenticated arbitrary file deletion on 1M WordPress sites. Update to 3.15.4 now. #AvadaBuilder #WordPress #CVE20268713 #FileDeletion #Wordfence #Vulnerability https://securityonline.info/avada-builder-vulnerability https://t.co/UMmWjDVWl8

    Post summary

    A critical Avada Builder CVE-2026-8713 allows unauthenticated file deletion on WordPress sites; users should update to version 3.15.4 immediately.

    020114890
    12.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-8713 - critical 🚨 Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion > The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file delet... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-8713 @pdnuclei #NucleiTem...

    Post summary

    The post announces CVE-2026-8713, detailing an unauthenticated arbitrary file deletion flaw in Avada (Fusion) Builder up to version 3.15.3, with a reference link for further information.

    00010363
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-8713: A PoC/exploit has been discovered for vulnerability CVE-2026-8713 PT ID: PT-2026-50846 Vendor: WordPress / themefusion Product: Avada (Fusion) Builder (WordPress plugin) Description: The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary…

    Post summary

    A proof‑of‑concept/exploit for CVE-2026-8713 has been identified, but no specific exploit code, active exploitation, patch details, or technical vulnerability description is provided.

    1000069
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-07-06T09:15:17.000Z Likes: 38 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-8713

    Post summary

    The post announces that a PoC/exploit exists for CVE-2026-8713, but offers no technical, patch, or exploitation details.

    1000058
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: CVE-2026-8713 is a critical Avada Builder vulnerability enabling unauthenticated

    Post summary

    The tweet announces the zero‑day CVE‑2026‑8713 as a critical flaw in Avada Builder that allows unauthenticated attacks, but provides no PoC, exploit, or mitigation details.

    1000058
    310 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Full Tweet CVE-2026-8713 is a critical Avada Builder vulnerability enabling unauthenticated arbitrary file deletion on 1M WordPress sites. Update to 3.15.4 now.

    Post summary

    The tweet alerts that CVE‑2026‑8713 is a critical Avada Builder flaw allowing unauthenticated file deletion on around 1 million WordPress sites and urges users to upgrade to version 3.15.4.

    1000054
    310 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-06-19T07:31:46.000Z Likes: 11 0day Intel: CVE-2026-8713 is a critical Avada Builder vulnerability enabling unauthenticated

    Post summary

    A tweet announces a critical zero‑day (CVE‑2026‑8713) in Avada Builder that enables unauthenticated access, but offers no PoC, exploit, patch info, or detailed technical data.

    1000065
    310 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-8713: CVE-2026-8713 is a critical Avada Builder vulnerability enabling unauthenticated arbitrary file deletion on 1M WordPress sites. Update to 3.15.4 now. #AvadaBuilder #WordPress #CVE20268713 #FileDeletion #Wordfence #Vulnerability

    Post summary

    The tweet warns that Avada Builder has a critical unauthenticated file deletion flaw (CVE-2026-8713) affecting many WordPress sites and recommends updating to version 3.15.4 immediately.

    1000070
    310 followersView on X
  • WPDigest@WPDigestio
    Patch

    🚨 Security Alert: If you use Avada Builder, update now. CVE-2026-8713 (CVSS 9.1 Critical) affects 1M+ WordPress sites and allows unauthenticated file deletion. * Update to v3.15.4 * Back up your site * Audit permissions #WordPress #Security #CVE20268713 https://t.co/U9fRrSvodj

    Post summary

    The tweet alerts users of the critical Avada Builder vulnerability CVE-2026-8713, which permits unauthenticated file deletion, and urges updating to v3.15.4 while backing up and auditing site permissions.

    0001093
    253 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Avada Builder の脆弱性 CVE-2026-8713:任意のファイル削除の恐れ https://iototsecnews.jp/2026/06/19/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/ この脆弱性 CVE-2026-8713 の主な原因は、プラグイン内の関数におけるファイルパスの検証不備にあります。ユーザーが入力したデータを処理するクリーンアップ機能において、適切なサニタイズやパスの正規化が行われていませんでした。そのため、プログラム側でディレクトリの境界を正しく制限できず、攻撃者が指定した不正なパスを受け入れてしまう状態になっています。この原因により、アップロード用フォルダ以外の重要なファイルまで削除されてしまい、最終的に Web サイト全体が乗っ取られる深刻な危険性につながります。ご利用のチームは、ご注意ください。 #AvadaBuilder #CVE20268713 #Vulnerability #WordPress

    Post summary

    The article announces CVE‑2026‑8713, detailing an unchecked file path issue in WordPress Avada Builder that could lead to arbitrary file deletion and site takeover, but offers no remediation or exploit evidence.

    01000191
    500 followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Avada Builder 3.15.4 fixes CVE-2026-8713: unauthenticated file deletion (CVSS 9.1). Delete wp-config.php, WordPress drops to setup mode, an attacker's path to RCE. Find affected sites: https://mysites.guru/blog/avada-builder-cve-2026-8713/?utm_source=twitter&utm_medium=social https://t.co/7GkJUFSCG9

    Post summary

    Avada Builder 3.15.4 releases a patch for CVE‑2026‑8713, an unauthenticated file‑deletion flaw that could allow remote code execution; affected sites are listed on the provided link.

    00010120
    2.5K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Avada Builder 3.15.4 fixes CVE-2026-8713: unauthenticated file deletion (CVSS 9.1). Delete wp-config.php, WordPress drops to setup mode, an attacker's path to RCE. Find affected sites: https://mysites.guru/blog/avada-builder-cve-2026-8713/?utm_source=twitter&utm_medium=social https://t.co/Kkj0REtYk2

    Post summary

    Avada Builder 3.15.4 issues a patch that mitigates CVE-2026-8713, a high‑severity vulnerability allowing unauthenticated file deletion leading to potential remote code execution on WordPress sites.

    00010126
    2.5K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Critical Flaw in WordPress Plugin Allows Arbitrary File Deletion on 1 Million Sites https://cyberpress.org/critical-flaw-in-wordpress-plugin/ "Tracked as CVE-2026-8713 with a CVSS score of 9.1 (Critical), the flaw allows unauthenticated attackers to delete arbitrary files on the server, …"

    Post summary

    A critical WordPress plugin vulnerability (CVE-2026-8713) permits unauthenticated attackers to delete arbitrary files, with a CVSS score of 9.1, impacting approximately one million sites.

    10000155
    3.5K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites https://gbhackers.com/critical-wordpress-plugin-bug/ "Identified as CVE-2026-8713 and assigned a CVSS score of 9.1, the vulnerability affects all plugin versions up to and including 3.15.3."

    Post summary

    A newly disclosed CVE‑2026‑8713, a critical WordPress plugin flaw that could permit file deletion, has a CVSS score of 9.1 and impacts all plugin versions up to 3.15.3.

    10000187
    3.5K followersView on X
  • Xploitzone@Xploitzone_01
    Disclosure

    🚨 Critical Avada WordPress bug CVE-2026-8713 Hackers can delete wp-config.php with a simple form submission no login needed! Over 1M sites at risk of full takeover & RCE. If you use Avada Builder, update NOW! [https://xploitzone.com/avada-wordpress-cve-2026-8713/] #WordPress #Avada #CVE20268713 https://t.co/yGT8vvavHt

    Post summary

    The tweet announces CVE‑2026‑8713, a critical AVADA WordPress flaw that permits unauthenticated deletion of wp‑config.php, threatening over 1M sites with full takeover and RCE; users are urged to update immediately.

    00000145
    10 followersView on X
  • Falcon Internet@falconinet
    Disclosure

    Avada Builder CVE-2026-8713: Delete wp-config.php, No Login Required https://www.falconinternet.net/blog/avada-builder-cve-2026-8713-wp-config-deletion-wordpress?ref=x #Security #WordPress https://t.co/YjPUVqpLgB

    Post summary

    The tweet announces a new WordPress vulnerability (CVE-2026-8713) that allows deletion of wp-config.php without login, directing readers to a blog for details.

    0000028
    18 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    General

    🚨 #CVE-2026-8713: The Silent WordPress Plugin Flaw That Could Erase Your Entire Website in Seconds + Video -Fact Checker: ✅: 1 ❌: 2 || 1/3 → Score: 33% 🤏🏻 -Prediction: 📈 2 Positive | 📉 1 Negative http://undercodenews.com/cve-2026-8713-the-silent-wordpress-plugin-flaw-that-could-erase-your-entire-website-in-seconds-video/

    Post summary

    The tweet merely points to a news article about CVE‑2026‑8713 without providing any technical details, exploit info, or patch status, making it a general mention.

    0000038
    956 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-8713 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in … https://www.cve.org/CVERecord?id=CVE-2026-8713 ----- Traducción: CVE-2026-8713 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑8713, noting it allows arbitrary file deletion in the Avada Builder plugin, but provides no PoC, exploit tools, active usage, or patch information.

    0000033
    82 followersView on X

Explore more