CVE-2026-8713
Last modified
CVE-2026-8713 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8713?
How severe is CVE-2026-8713?
How do I fix CVE-2026-8713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87124Vulnerability in the Oracle iRecruitment product of Oracle E…7.7
- CVE-2026-87125Vulnerability in the Oracle Financials for Asia/Pacific prod…8.3
- CVE-2026-87126Vulnerability in the Oracle Report Manager product of Oracle…7.1
- CVE-2026-87127Vulnerability in the Oracle Purchasing product of Oracle E-B…7.7
- CVE-2026-87128Vulnerability in the Oracle Hyperion Data Relationship Manag…9.1
- CVE-2026-87129Vulnerability in the Oracle Hyperion Data Relationship Manag…9.1
- CVE-2026-87130Vulnerability in the Oracle Hyperion Data Relationship Manag…7.4
- CVE-2026-87131Vulnerability in the Oracle Hyperion Data Relationship Manag…7.6
- CVE-2026-87132Vulnerability in the Oracle Hyperion Data Relationship Manag…7.6
- CVE-2026-87133Vulnerability in the Oracle Hyperion Data Relationship Manag…7.6
- CVE-2026-87134Vulnerability in the Oracle Hyperion Data Relationship Manag…7.7
- CVE-2026-87135Vulnerability in the Oracle Hyperion Data Relationship Manag…7.1
Are you affected by CVE-2026-8713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
