Over a million WordPress sites hit in plugin flaw — so patch now or face the consequences



  • Wordfence disclosed two flaws in Avada Builder, a WordPress plugin with around 1 million active installs
  • CVE‑2026‑4782 (Arbitrary File Read, medium severity) requires subscriber‑level access; CVE‑2026‑4798 (SQL injection, high severity) exploitable unauthenticated
  • Patches released in April and May 2026; users advised to update to v3.15.3+; researcher Rafie Muhammad earned ~$4,500 bounty

A popular WordPress plugin with roughly a million active installations contained two vulnerabilities that could have allowed malicious actors to exfiltrate sensitive data, such as password hashes and other valuable information.

Security researchers at Wordfence said they were tipped off by a researcher Rafie Muhammad about the existence of an Arbitrary File Read and an SQL Injection vulnerability in Avada Builder.

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img