Avada Builder WordPress plugin flaws allow site credential theft
Source: BleepingComputer · Category: Supply Chain
Avada Builder WordPress plugin (1M+ active installations) has two critical vulnerabilities allowing arbitrary file reads and database credential theft. Assess whether the firm uses this plugin on client portals or internal WordPress sites; if compromised, client data and firm credentials are at risk.