Arbitrary File Read & SQL Injection in Avada Builder
Avada (Fusion) Builder version 3.15.1 has two vulnerabilities: Arbitrary file read (e.g. leak wp-config.php) and unauthenticated SQL injection.
17 May 2026
Read moreUnauthenticated SQL Injection in Ally
Versions of Ally (One Click Accessibility) up to and including 4.0.3 are open to an unauthenticated SQL injection vulnerability. An attacker can extract sensitive data from the database, without logging in.
10 April 2026
Read more