Threat reportVulnerabilityTL-2026-0874
CVE-2026-8713: Avada (Fusion) Builder WordPress Plugin Unauthenticated Path Traversal Arbitrary File Deletion
CVE-2026-8713 (TL-2026-0874) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-06-19. It has no confirmed attribution, affects ThemeFusion Avada (Fusion) Builder, references 1 CVE (CVE-2026-8713), maps to 15 MITRE ATT&CK techniques (T1059, T1070, T1083), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0874
- Threat ID
- TL-2026-0874
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, media, ecommerce, small-business, agencies, education, hospitality
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
How CVE-2026-8713 works
An unauthenticated path-traversal flaw (CVE-2026-8713, CWE-22) in the maybe_delete_files() method of the Avada (Fusion) Builder WordPress plugin's Fusion_Form_DB_Entries class lets remote attackers delete arbitrary server files — including wp-config.php — leading to full-site takeover and remote code execution. Affects all versions through 3.15.3 across more than 1 million installations; fixed in 3.15.4.
CVE-2026-8713 is a critical (CVSS 9.1) unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress, developed by ThemeFusion and installed on over 1,000,000 sites. The root cause is insufficient file path validation in the maybe_delete_files() method of the Fusion_Form_DB_Entries class. The function reconstructs a filesystem path by string-replacing the public upload URL prefix with the local upload directory path, but performs no realpath() resolution or directory-containment check, so directory-traversal sequences (e.g. ../../../) survive into the final path passed to the file-deletion routine. A representative payload is /wp-content/uploads/fusion-forms/../../../wp-config.php, which resolves outside the intended fusion-forms upload directory.
Exploitation requires a published Avada form configured to save submissions to the database. An unauthenticated attacker submits a crafted entry to the wp_ajax_nopriv_fusion_form_submit_ajax handler (reachable via /wp-admin/admin-ajax.php) embedding a path-traversal payload in a file-reference field, while simultaneously controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup. The planted entry is then automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction, causing the targeted file to be deleted.
Deleting wp-config.php forces WordPress into its initial setup/installation mode. An attacker can then point the site at an attacker-controlled database, complete the installer (creating an attacker-owned administrator account), and deploy arbitrary PHP — achieving full remote code execution and complete site takeover. Other high-value deletion targets (.htaccess, plugin/theme security files) can degrade defenses, inhibit recovery, or cause denial of service.
The issue was reported on 2026-05-13 through the Wordfence Bug Bounty Program by researcher 'daroo' (awarded USD 3,600). ThemeFusion was notified on 2026-05-15, submitted a patch on 2026-05-19, and shipped the fix in Avada (Fusion) Builder 3.15.4 on 2026-06-02. Wordfence published the advisory on 2026-06-18; the CVE record was published 2026-06-19. The fix adds realpath-based containment validation to maybe_delete_files() so deletion targets must resolve inside the intended fusion-forms upload directory. No public proof-of-concept and no confirmed in-the-wild exploitation have been reported at disclosure time; the Wordfence firewall detects and blocks the path-traversal pattern in form submissions. This is one of several file-handling weaknesses reported in the Fusion Builder family (an authenticated arbitrary file read was previously tracked by Patchstack in v3.15.2), underscoring the plugin's recurring path-validation risk.
MITRE ATT&CK techniques used in TL-2026-0874
Execution
T1059 Command and Scripting Interpreter
Defense Evasion
Discovery
T1083 File and Directory Discovery
Persistence
T1136 Create Account; T1505 Server Software Component
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery; T1499 Endpoint Denial of Service; T1565 Data Manipulation
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning
defense-impairment
Affected products and versions in CVE-2026-8713
- ThemeFusion — Avada (Fusion) Builder
Vulnerable versions: <= 3.15.3
Fixed in: 3.15.4
Remediation for CVE-2026-8713
Patches
- Avada (Fusion) Builder 3.15.4 (released 2026-06-02) — adds realpath-based containment validation to maybe_delete_files()
Immediate actions
- Update Avada (Fusion) Builder to version 3.15.4 or later immediately
- Audit all publicly published Avada forms and temporarily unpublish or disable any form configured to save entries to the database until patched
- Verify integrity/existence of wp-config.php and .htaccess and restore from backup if missing or altered
Workarounds
- Disable database storage of Avada form entries (store via email only)
- Unpublish vulnerable forms
- Block or rate-limit unauthenticated requests to /wp-admin/admin-ajax.php with action=fusion_form_submit_ajax at the WAF/reverse proxy
Longer-term hardening
- Deploy a Web Application Firewall (WAF) with rules blocking path-traversal sequences in admin-ajax.php form submissions
- Apply least-privilege filesystem permissions so the web server user cannot delete files outside the uploads directory
- Establish file-integrity monitoring and off-site backups of wp-config.php and core WordPress files
- Inventory and minimize WordPress plugins exposing unauthenticated wp_ajax_nopriv handlers
CVEs associated with CVE-2026-8713
CVE-2026-8713
Weaknesses (CWE) in CVE-2026-8713
Timeline of CVE-2026-8713
- Vulnerability reported to the Wordfence Bug Bounty Program by security researcher 'daroo'.
- Wordfence validated the finding and responsibly disclosed it to vendor ThemeFusion via the Vulnerability Management Portal.
- ThemeFusion submitted a patch adding realpath-based containment validation to maybe_delete_files().
- Avada (Fusion) Builder 3.15.4 released with the fix; researcher 'daroo' awarded USD 3,600.
- Wordfence firewall rules detect and block path-traversal payloads in Avada form submissions, protecting firewall users against exploitation attempts.
- Wordfence published the public advisory; CVE-2026-8713 details (CVSS 9.1, CWE-22) made public.
- At publication, no public proof-of-concept and no confirmed in-the-wild exploitation reported; over 1,000,000 installations remain at risk until updated to 3.15.4.
- CVE-2026-8713 record published in vulnerability databases (NVD, CIRCL Vulnerability-Lookup); CNA Wordfence.
Sources cited for CVE-2026-8713
- Wordfence Threat Intelligence — CVE-2026-8713 advisory
- Wordfence Blog — Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
- WordPress.org Plugin SVN — fusion-builder class-fusion-form-db-entries.php (vulnerable maybe_delete_files)
- NVD — CVE-2026-8713 detail
- CIRCL Vulnerability-Lookup — CVE-2026-8713
- Cyber Security News — Avada WordPress Plugin Vulnerability Let Attackers Delete Arbitrary Files
- GBHackers — Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites
- Malware.news — Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
- Patchstack — Avada (Fusion) Builder related arbitrary file read vulnerability (plugin <= 3.15.2)
Detection coverage for TL-2026-0874
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0874 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.