PT-2026-40584 · WordPress · Avada Builder
Rafie Muhammad
·
Published
2026-05-13
·
Updated
2026-05-18
·
CVE-2026-4798
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Avada Builder versions prior to 3.15.2
Description
The Avada Builder plugin for WordPress contains a time-based SQL Injection, a technique where an attacker sends queries that cause the database to pause for a specific duration to determine if a condition is true. This occurs via the 'product order' parameter due to insufficient escaping of user-supplied data and lack of proper preparation of the SQL query. Unauthenticated attackers can append additional SQL queries to extract sensitive information from the database. This issue only affects sites where WooCommerce was previously installed and subsequently deactivated. Approximately 1 million sites are estimated to be at risk.
Recommendations
Update to a version newer than 3.15.1.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avada Builder