The Avada Builder plugin flaws allow low level users to read server files and unauthenticated attackers to steal database credentials.