CVE-2026-4798
CVSS 7.5 HIGH: the Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in… EPSS 0.5% (37º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Avada Builder trasforma l’accesso a basso privilegio in una perdita di secret lato server. Un account a livello subscriber può leggere wp-config.php, il che significa che le credenziali del database e i salt possono fuoriuscire da un singolo bug del plugin invece che da una compromissione completa admin.
2 fonti · 15 mag
CVSS 7.5 HIGH: the Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in… EPSS 0.5% (37º percentile).
CVSS 6.5 MEDIUM: the Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including… EPSS 0.5% (37º percentile).
BleepingComputer
Avada Builder WordPress plugin flaws allow site credential theft
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database.
originaleInfosecurity Magazine
Avada Builder Flaws Expose One Million WordPress Sites
Avada Builder flaws allowed file read and SQL injection on one million WordPress sites
originalePart of the PlainSec briefing for 2026-05-15
Every edition of this story: Le vulnerabilità di Avada Builder possono esporre i secret di WordPress