CVE-2026-4798
CVSS 7.5 HIGH: the Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in… EPSS 0.5% (39th percentile).
Vulnerabilities & Exploits · Web App Attack
Avada Builder turns low-privilege access into a server-side secret leak. A subscriber-level account can read wp-config.php, which means database credentials and salts can fall out of a single plugin bug instead of a full admin compromise.
Wordfence says the two flaws affect about one million WordPress sites. CVE-2026-4782 is an arbitrary file read, and CVE-2026-4798 is an unauthenticated SQL injection on sites that had WooCommerce installed and later deactivated; the fixed release is 3.15.3, with 3.15.2 only partially addressing the issue.
The real danger is second-order exposure. If wp-config.php was readable, the compromise can outlast the patch because stolen credentials and keys may still open the database or other systems that reused them.
2 sources · May 15
CVSS 7.5 HIGH: the Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in… EPSS 0.5% (39th percentile).
CVSS 6.5 MEDIUM: the Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including… EPSS 0.5% (37th percentile).
BleepingComputer
Avada Builder WordPress plugin flaws allow site credential theft
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database.
originalInfosecurity Magazine
Avada Builder Flaws Expose One Million WordPress Sites
Avada Builder flaws allowed file read and SQL injection on one million WordPress sites
originalPart of the PlainSec briefing for 2026-05-15
Every edition of this story: Avada Builder Flaws Can Expose WordPress Secrets