/Vulnerability Library

Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion

CVE-2026-8713
Verified

Description

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function. An unauthenticated attacker can delete arbitrary files on the server by manipulating the file_path parameter in the fusion_form_maybe_delete_files AJAX action. Deleting critical files like wp-config.php can lead to complete site takeover via reinstallation. This template detects the vulnerable version via homepage asset URL versioning (primary) and readme.txt Stable tag (fallback).

Severity

Critical

CVSS Score

9.1

Exploit Probability

3%

Affected Product

fusion-builder

Published Date

July 27, 2026

Template Author

rool-machine

CVE-2026-8713.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE ID:
cve-2026-8713
CWE ID:
cwe-22

References

https://www.wordfence.com/blog/2026/06/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/https://nvd.nist.gov/vuln/detail/CVE-2026-8713

Remediation Steps

Upgrade the Avada Builder (Fusion Builder) plugin to version 3.15.4 or later.