A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.
The exploit chains six security issues into a zero-click attack. The flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score.
The attack comprises exploits for authorization, input-validation, trust-boundary, and file-handling weaknesses, which must be executed in a specific order to enable arbitrary PHP code execution on a target server.
Hackers who successfully exploit these vulnerabilities could fully compromise websites for malicious activities ranging from planting malware and accessing databases to redirecting visitors to malicious sites or adding rogue admin accounts.
CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16, researchers at Defiant’s Wordfence team say in a report on Tuesday.
While ThemeFusion, the developer behind Avada and Fusion Builder, fixed the vulnerability, Wordfence is not sharing complete technical details to give administrators sufficient time to install the latest updates and has only provided the following attack chain overview:
Although exploitation requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target website, Wordfence researchers clarified for BleepingComputer that “Fusion Builder is a required plugin for the Avada theme.”
“Therefore all sites running the Avada theme will also be running the Fusion Builder plugin,” the researchers said.
Avada theme is a very popular product, with more than 1 million sales, and because Fusion Builder is installed with it “the prerequisites don’t narrow the pool of potential targets,” Wordfence explained.
“Any site that has the Avada theme installed is going to be exploitable.”
Wordfence discovered the six-step vulnerability chain using an internal agentic framework called Argus, which also developed proof-of-concept exploit code, all in about two hours.
Argus found and successfully reproduced the flaw on July 30, and the researchers shared the full details to the vendor on August 5. ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday.
Update [08/27]: Article updated with clarification from Wordfence that the Avada theme installs together with Fusion Builder, so any site running an outdated version of the theme can be compromised by exploiting CVE-2026-18431.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
One threat actor responsible for 83% of recent Ivanti RCE attacks
Hackers target WordPress sites in miniOrange auth bypass attacks
CISA orders urgent patching of actively exploited Zimbra flaw
Microsoft patches max severity code execution, privilege escalation flaws
Ubiquiti patches three max severity security vulnerabilities
Police arrests dozens of suspects in global cybercrime crackdown
Microsoft Teams now lets admins block external bots from meetings
Discover why encryption and key management are critical for modern business.
Discover how least agency keeps your AI tools capable, controlled, and secure.
Overdue a password health-check? Audit your Active Directory for free
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


