# CVE-2026-8713: Avada (Fusion) Builder WordPress Plugin Unauthenticated Path Traversal Arbitrary File Deletion

> An unauthenticated path-traversal flaw (CVE-2026-8713, CWE-22) in the maybe_delete_files() method of the Avada (Fusion) Builder WordPress plugin's Fusion_Form_DB_Entries class lets remote attackers delete arbitrary server files — including wp-config.php — leading to full-site takeover and remote code execution. Affects all versions through 3.15.3 across more than 1 million installations; fixed in 3.15.4.

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0874
- **ID:** TL-2026-0874
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8713

## Description

CVE-2026-8713 is a critical (CVSS 9.1) unauthenticated arbitrary file deletion vulnerability in the Avada (Fusion) Builder plugin for WordPress, developed by ThemeFusion and installed on over 1,000,000 sites. The root cause is insufficient file path validation in the maybe_delete_files() method of the Fusion_Form_DB_Entries class. The function reconstructs a filesystem path by string-replacing the public upload URL prefix with the local upload directory path, but performs no realpath() resolution or directory-containment check, so directory-traversal sequences (e.g. ../../../) survive into the final path passed to the file-deletion routine. A representative payload is /wp-content/uploads/fusion-forms/../../../wp-config.php, which resolves outside the intended fusion-forms upload directory.

Exploitation requires a published Avada form configured to save submissions to the database. An unauthenticated attacker submits a crafted entry to the wp_ajax_nopriv_fusion_form_submit_ajax handler (reachable via /wp-admin/admin-ajax.php) embedding a path-traversal payload in a file-reference field, while simultaneously controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup. The planted entry is then automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction, causing the targeted file to be deleted.

Deleting wp-config.php forces WordPress into its initial setup/installation mode. An attacker can then point the site at an attacker-controlled database, complete the installer (creating an attacker-owned administrator account), and deploy arbitrary PHP — achieving full remote code execution and complete site takeover. Other high-value deletion targets (.htaccess, plugin/theme security files) can degrade defenses, inhibit recovery, or cause denial of service.

The issue was reported on 2026-05-13 through the Wordfence Bug Bounty Program by researcher 'daroo' (awarded USD 3,600). ThemeFusion was notified on 2026-05-15, submitted a patch on 2026-05-19, and shipped the fix in Avada (Fusion) Builder 3.15.4 on 2026-06-02. Wordfence published the advisory on 2026-06-18; the CVE record was published 2026-06-19. The fix adds realpath-based containment validation to maybe_delete_files() so deletion targets must resolve inside the intended fusion-forms upload directory. No public proof-of-concept and no confirmed in-the-wild exploitation have been reported at disclosure time; the Wordfence firewall detects and blocks the path-traversal pattern in form submissions. This is one of several file-handling weaknesses reported in the Fusion Builder family (an authenticated arbitrary file read was previously tracked by Patchstack in v3.15.2), underscoring the plugin's recurring path-validation risk.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1136 Create Account
- T1070 Indicator Removal
- T1685 Disable or Modify Tools
- T1083 File and Directory Discovery
- T1485 Data Destruction
- T1490 Inhibit System Recovery
- T1499 Endpoint Denial of Service
- T1565 Data Manipulation

## Sources

- [Wordfence Threat Intelligence — CVE-2026-8713 advisory](https://www.wordfence.com/threat-intel/vulnerabilities/id/e4bfb72e-023b-4bfd-b125-91f6ac2f200f?source=cve)
- [Wordfence Blog — Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin](https://www.wordfence.com/blog/2026/06/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/)
- [WordPress.org Plugin SVN — fusion-builder class-fusion-form-db-entries.php (vulnerable maybe_delete_files)](https://plugins.trac.wordpress.org/browser/fusion-builder/trunk/inc/class-fusion-form-db-entries.php#L79)
- [NVD — CVE-2026-8713 detail](https://nvd.nist.gov/vuln/detail/CVE-2026-8713)
- [CIRCL Vulnerability-Lookup — CVE-2026-8713](https://vulnerability.circl.lu/vuln/cve-2026-8713)
- [Cyber Security News — Avada WordPress Plugin Vulnerability Let Attackers Delete Arbitrary Files](https://cybersecuritynews.com/avada-wordpress-plugin-vulnerability/)
- [GBHackers — Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites](https://gbhackers.com/critical-wordpress-plugin-bug/)
- [Malware.news — Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin](https://malware.news/t/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/108038)
- [Patchstack — Avada (Fusion) Builder related arbitrary file read vulnerability (plugin <= 3.15.2)](https://patchstack.com/database/wordpress/plugin/fusion-builder/vulnerability/wordpress-avada-fusion-builder-plugin-3-15-2-authenticated-subscriber-arbitrary-file-read-vulnerability)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0874
