← Back to feed
vendor Wordfence Blog

Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin

Wordfence Blog WordPress

On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin...

T1190
Read the full story Wordfence Blog →

Related Coverage

vendor CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days Qualys Blog · Aug 25 vendor The Cloudflare Blog – Brought to you by EmDash Cloudflare Blog · Aug 24 vendor Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) Rapid7 Blog · Aug 24