Return to Global Matrix
CLASSIFIED: EYES ONLY

Avada Builder WordPress plugin flaws allow site credential theft

TELEMETRY SUMMARY DECRYPTION

SITREP: Two vulnerabilities have been identified in the Avada Builder plugin for WordPress, which is currently active on approximately one million installations. These flaws enable unauthorized access to read arbitrary files and extract sensitive information from the database. TACTICAL ASSESSMENT: The widespread use of the Avada Builder plugin increases the potential impact of these vulnerabilities, posing significant risks to website security and user data. This incident highlights the ongoing challenges in maintaining cybersecurity within widely used web applications. PROJECTED VECTORS: It is likely that hackers will exploit these vulnerabilities to target a large number of websites, leading to potential data breaches and increased cybercrime activity.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-05-15

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME05/1516:22 ZULU
AUTHORSYSTEM.AUTO[992]