Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function. An unauthenticated attacker can delete arbitrary files on the server by manipulating the file_path parameter in the fusion_form_maybe_delete_files AJAX action. Deleting critical files like wp-config.php can lead to complete site takeover via reinstallation. This template detects the vulnerable version via homepage asset URL versioning (primary) and readme.txt Stable tag (fallback).