Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Two vulnerabilities in the Avada Builder WordPress plugin expose approximately one million websites to credential theft and full database compromise. An authenticated attacker can read the site’s configuration file, obtaining database passwords and encryption keys; a separate flaw allows an unauthenticated attacker to extract user password hashes without logging in, provided WooCommerce was ever installed on the site. The vendor released a fully patched version (3.15.3) on May 12, 2026; any site still running version 3.15.2 or earlier is at risk.

Author

Tech Jacks Solutions