Critical Avada WordPress theme flaw enables zero-click RCE
ID: a07793fb-7776-5d31-a66f-abd50260fbce
STIX ID: report--a07793fb-7776-5d31-a66f-abd50260fbce
Feed Name: Bleeping Computer
Wordfence disclosed a critical, six-step vulnerability chain (CVE-2026-18431, CVSS 9.8) in the Avada WordPress theme and Fusion Builder plugin that can be chained into a zero-click remote PHP code execution. Exploitation requires both a vulnerable Avada version (<= 7.16) and Fusion Builder (<= 3.16) on the same site, narrowing targets despite Avada's large install base; ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 and Wordfence withheld full technical details to allow administrators time to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
