Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
Wordfence's AI-assisted Argus found a six-step critical RCE chain in the Avada WordPress theme, which has more than one million sales.
Wordfence reports that its Argus research uncovered a complex six-step exploit chain yielding critical remote code execution in the Avada WordPress theme, one of the best-selling themes with over one million sales. The company also notes AI-assisted submissions to its bug bounty program grew from 16% to roughly two-thirds of all reports in recent months. Sites running Avada should apply the patched release.
- Six-step exploit chain achieves critical RCE in Avada theme
- Avada's 1 million+ sales give the flaw broad exposure
- Discovered via Wordfence Argus AI-assisted research
- AI-assisted bug bounty reports now about two-thirds of submissions
A year ago we wrote that we'd put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted reports to our bug bounty program had gone from 16% to about two-thirds of everything we received, and it wasn’t slowing down. The post Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales appeared first on Wordfence.
This source does not provide full text. Read it at wordfence.com.