Liquid Web Status · History · Incident #4940
RESOLVEDSecurity Advisory: Update Avada Builder and UpdraftPlus WordPress Plugins Immediately
Minor · Started Jun 26, 2026 · 1:23 AM
$HTTP_PROTOCOL = (isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1)) || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https') ? 'https://' : 'http://'; $SITE_URL = $HTTP_PROTOCOL . $_SERVER['SERVER_NAME'] . '/'; ?>
Liquid Web Status · History · Incident #4940
RESOLVEDMinor · Started Jun 26, 2026 · 1:23 AM
Duration
13d 8h 52m
Severity
Minor
Detection lead
—
User reports
—
Summary
This advisory is now being closed. We encourage our customers to ensure that any affected WordPress plugins have been updated to the latest available versions and continue following WordPress security best practices. If you believe your website may have been impacted or require assistance, please contact our Support team.
Started
Jun 26, 2026 · 1:23 AM
Resolved
Jul 9, 2026 · 10:15 AM
Duration
13d 8h 52m
Severity
None
Event timeline
Investigating
Jun 26 · 1:23 AM Liquid WebWe are advising all customers using WordPress to verify that the following plugins are updated to the latest available versions. Recently disclosed vulnerabilities affect older versions of these plugins: CVE-2026-6279 – Avada Builder (Fusion Builder) – Unauthenticated Remote Code Execution Affected versions: 3.15.2 and earlier CVE-2026-10795 – UpdraftPlus Backup Plugin – Authentication Bypass Affected versions: 1.26.4 and earlier These vulnerabilities may allow unauthenticated attackers to gain control of vulnerable WordPress sites and compromise WordPress user accounts if the plugins have not been updated to the latest available versions. If your website uses either of these plugins, we strongly recommend that you: Update the affected plugin(s) to the latest available version immediately. Review your WordPress installation for any unexpected administrator accounts, plugins, or modified files. Contact our Support team if you believe your website has been affected or if you need assistance reviewing your installation.
Resolved
Jul 9 · 10:15 AM Liquid WebThis advisory is now being closed. We encourage our customers to ensure that any affected WordPress plugins have been updated to the latest available versions and continue following WordPress security best practices. If you believe your website may have been impacted or require assistance, please contact our Support team.
Pattern
WP2Shell Wordpress Core Critical Remote Code Execution Vulnerabilities, CVE-2026-60137 and CVE-2026-63030
Jul 17, 2026
View incident →Power Outage in Phoenix, AZ
Jul 16, 2026 · 4h 23m
View incident →Apache Service Disruption Following ModSecurity Update
Jul 15, 2026
View incident →Pulsetic catches degradations minutes before vendors acknowledge them.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026