Threat reportVulnerabilityTL-2026-0874

CVE-2026-8713: Avada (Fusion) Builder WordPress Plugin Unauthenticated Path Traversal Arbitrary File Deletion

criticalACTIVE

CVE-2026-8713 (TL-2026-0874) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-06-19. It has no confirmed attribution, affects ThemeFusion Avada (Fusion) Builder, references 1 CVE (CVE-2026-8713), maps to 15 MITRE ATT&CK techniques (T1059, T1070, T1083), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
9.1/10Critical
CVEs
1Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0874

Threat ID
TL-2026-0874
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, media, ecommerce, small-business, agencies, education, hospitality
Target regions
Global
Detection rules
9
Indicators of compromise
18

How CVE-2026-8713 works

An unauthenticated path-traversal flaw (CVE-2026-8713, CWE-22) in the maybe_delete_files() method of the Avada (Fusion) Builder WordPress plugin's Fusion_Form_DB_Entries class lets remote attackers delete arbitrary server files — including wp-config.php — leading to full-site takeover and remote code execution. Affects all versions through 3.15.3 across more than 1 million installations; fixed in 3.15.4.

CVE-2026-8713 is a critical (CVSS 9.1) unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress, developed by ThemeFusion and installed on over 1,000,000 sites. The root cause is insufficient file path validation in the maybe_delete_files() method of the Fusion_Form_DB_Entries class. The function reconstructs a filesystem path by string-replacing the public upload URL prefix with the local upload directory path, but performs no realpath() resolution or directory-containment check, so directory-traversal sequences (e.g. ../../../) survive into the final path passed to the file-deletion routine. A representative payload is /wp-content/uploads/fusion-forms/../../../wp-config.php, which resolves outside the intended fusion-forms upload directory.

Exploitation requires a published Avada form configured to save submissions to the database. An unauthenticated attacker submits a crafted entry to the wp_ajax_nopriv_fusion_form_submit_ajax handler (reachable via /wp-admin/admin-ajax.php) embedding a path-traversal payload in a file-reference field, while simultaneously controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup. The planted entry is then automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction, causing the targeted file to be deleted.

Deleting wp-config.php forces WordPress into its initial setup/installation mode. An attacker can then point the site at an attacker-controlled database, complete the installer (creating an attacker-owned administrator account), and deploy arbitrary PHP — achieving full remote code execution and complete site takeover. Other high-value deletion targets (.htaccess, plugin/theme security files) can degrade defenses, inhibit recovery, or cause denial of service.

The issue was reported on 2026-05-13 through the Wordfence Bug Bounty Program by researcher 'daroo' (awarded USD 3,600). ThemeFusion was notified on 2026-05-15, submitted a patch on 2026-05-19, and shipped the fix in Avada (Fusion) Builder 3.15.4 on 2026-06-02. Wordfence published the advisory on 2026-06-18; the CVE record was published 2026-06-19. The fix adds realpath-based containment validation to maybe_delete_files() so deletion targets must resolve inside the intended fusion-forms upload directory. No public proof-of-concept and no confirmed in-the-wild exploitation have been reported at disclosure time; the Wordfence firewall detects and blocks the path-traversal pattern in form submissions. This is one of several file-handling weaknesses reported in the Fusion Builder family (an authenticated arbitrary file read was previously tracked by Patchstack in v3.15.2), underscoring the plugin's recurring path-validation risk.

MITRE ATT&CK techniques used in TL-2026-0874

Execution

T1059 Command and Scripting Interpreter

Defense Evasion

T1070 Indicator Removal

Discovery

T1083 File and Directory Discovery

Persistence

T1136 Create Account; T1505 Server Software Component

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery; T1499 Endpoint Denial of Service; T1565 Data Manipulation

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CVE-2026-8713

  • ThemeFusion — Avada (Fusion) Builder
    Vulnerable versions: <= 3.15.3
    Fixed in: 3.15.4

Remediation for CVE-2026-8713

Patches

  • Avada (Fusion) Builder 3.15.4 (released 2026-06-02) — adds realpath-based containment validation to maybe_delete_files()

Immediate actions

  • Update Avada (Fusion) Builder to version 3.15.4 or later immediately
  • Audit all publicly published Avada forms and temporarily unpublish or disable any form configured to save entries to the database until patched
  • Verify integrity/existence of wp-config.php and .htaccess and restore from backup if missing or altered

Workarounds

  • Disable database storage of Avada form entries (store via email only)
  • Unpublish vulnerable forms
  • Block or rate-limit unauthenticated requests to /wp-admin/admin-ajax.php with action=fusion_form_submit_ajax at the WAF/reverse proxy

Longer-term hardening

  • Deploy a Web Application Firewall (WAF) with rules blocking path-traversal sequences in admin-ajax.php form submissions
  • Apply least-privilege filesystem permissions so the web server user cannot delete files outside the uploads directory
  • Establish file-integrity monitoring and off-site backups of wp-config.php and core WordPress files
  • Inventory and minimize WordPress plugins exposing unauthenticated wp_ajax_nopriv handlers

CVEs associated with CVE-2026-8713

CVE-2026-8713

Weaknesses (CWE) in CVE-2026-8713

CWE-22

Timeline of CVE-2026-8713

  • Vulnerability reported to the Wordfence Bug Bounty Program by security researcher 'daroo'.
  • Wordfence validated the finding and responsibly disclosed it to vendor ThemeFusion via the Vulnerability Management Portal.
  • ThemeFusion submitted a patch adding realpath-based containment validation to maybe_delete_files().
  • Avada (Fusion) Builder 3.15.4 released with the fix; researcher 'daroo' awarded USD 3,600.
  • Wordfence firewall rules detect and block path-traversal payloads in Avada form submissions, protecting firewall users against exploitation attempts.
  • Wordfence published the public advisory; CVE-2026-8713 details (CVSS 9.1, CWE-22) made public.
  • At publication, no public proof-of-concept and no confirmed in-the-wild exploitation reported; over 1,000,000 installations remain at risk until updated to 3.15.4.
  • CVE-2026-8713 record published in vulnerability databases (NVD, CIRCL Vulnerability-Lookup); CNA Wordfence.

Sources cited for CVE-2026-8713

Detection coverage for TL-2026-0874

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0874 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats