Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion
CVE-2026-8713
Verified
Description
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function. An unauthenticated attacker can delete arbitrary files on the server by manipulating the file_path parameter in the fusion_form_maybe_delete_files AJAX action. Deleting critical files like wp-config.php can lead to complete site takeover via reinstallation. This template detects the vulnerable version via homepage asset URL versioning (primary) and readme.txt Stable tag (fallback).
Severity
Critical
CVSS Score
9.1
Exploit Probability
3%
Affected Product
fusion-builder
Published Date
July 27, 2026
Template Author
rool-machine
CVE-2026-8713.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE ID:
cve-2026-8713
CWE ID:
cwe-22
Remediation Steps
Upgrade the Avada Builder (Fusion Builder) plugin to version 3.15.4 or later.