Executive brief
Avada Builder, a popular page-building tool for WordPress websites, contains a security flaw that allows unauthorized individuals to access sensitive information from the site's database. By sending specially crafted requests, an attacker can bypass security measures to extract data such as user details or configuration settings. This vulnerability specifically affects sites where the WooCommerce plugin was previously installed and then deactivated.
Technical details
The Avada Builder plugin for WordPress is vulnerable to a time-based SQL injection vulnerability due to insufficient escaping of the 'product_order' parameter and a lack of proper SQL query preparation. An unauthenticated attacker can exploit this by appending malicious SQL commands to existing queries via a network request. Successful exploitation allows for the extraction of sensitive data from the WordPress database. A specific precondition for this vulnerability is that the WooCommerce plugin must have been previously active on the site and subsequently deactivated. The issue is present in all versions up to and including 3.15.1.
Affected products
- ThemeFusion Avada Builder Up to and including 3.15.1
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory