logo

Critical Avada WordPress theme flaw enables zero-click RCE

ID: a07793fb-7776-5d31-a66f-abd50260fbce

STIX ID: report--a07793fb-7776-5d31-a66f-abd50260fbce

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Bill Toulas

...
...

Wordfence disclosed a critical, six-step vulnerability chain (CVE-2026-18431, CVSS 9.8) in the Avada WordPress theme and Fusion Builder plugin that can be chained into a zero-click remote PHP code execution. Exploitation requires both a vulnerable Avada version (<= 7.16) and Fusion Builder (<= 3.16) on the same site, narrowing targets despite Avada's large install base; ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 and Wordfence withheld full technical details to allow administrators time to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.