ZeroHour
Wordfencepublished ()ingested Alex Thomas

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

highVulnerabilityimportance 55
AI summary · glm-5.3-flash

Wordfence's AI-assisted Argus found a six-step critical RCE chain in the Avada WordPress theme, which has more than one million sales.

Wordfence reports that its Argus research uncovered a complex six-step exploit chain yielding critical remote code execution in the Avada WordPress theme, one of the best-selling themes with over one million sales. The company also notes AI-assisted submissions to its bug bounty program grew from 16% to roughly two-thirds of all reports in recent months. Sites running Avada should apply the patched release.

  • Six-step exploit chain achieves critical RCE in Avada theme
  • Avada's 1 million+ sales give the flaw broad exposure
  • Discovered via Wordfence Argus AI-assisted research
  • AI-assisted bug bounty reports now about two-thirds of submissions
Full article

A year ago we wrote that we'd put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted reports to our bug bounty program had gone from 16% to about two-thirds of everything we received, and it wasn’t slowing down. The post Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales appeared first on Wordfence.

This source does not provide full text. Read it at wordfence.com.