
A chain of critical vulnerabilities in the popular Avada WordPress theme could be used by an unauthorized attacker to execute arbitrary PHP code on the server.
The exploit combines six security issues into a zero-click attack. The flaws are collectively tracked as CVE-2026-18431 and have received a Critical Severity Score of 9.8.
The attack includes exploits for authorization, input validation, trust boundary, and file handling weaknesses that must be executed in a specific order to enable arbitrary PHP code execution on a target server.
Hackers who successfully exploit these vulnerabilities can completely compromise websites for malicious activities ranging from planting malware and accessing databases to redirecting visitors to malicious sites or adding fraudulent administrator accounts.
CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16, say researchers from Defiant’s Wordfence team in report on Tuesday.
While ThemeFusion, the developer behind Avada and Fusion Builder, patched the vulnerability, Wordfence did not share full technical details to give administrators enough time to install the latest updates and only provided the following overview of the attack chain:
- Disclosure of attacker-controlled input via public request
- Passing this input to functionality restricted to anonymous users
- Calling a privileged component outside the intended context
- Using request data to influence trusted state
- Access to an insufficiently protected administrative operation
- Bypassing file processing restrictions on what can be written and where
The exploit requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target website.
The Avada theme is quite popular, with more than 1 million sales, so CVE-2026-18431 compromises a significant number of sites.
“Fusion Builder is a required plugin for the Avada theme. Therefore, all sites working with the Avada theme will also work with the Fusion Builder plugin,” Wordfence told BleepingComputer.
“(That being said…) prerequisites do not narrow the pool of potential targets. Any site that has an Avada theme installed will be exploited.”
Wordfence discovered the vulnerability’s six-step chain using an internal agent framework called Argus, which also developed proof-of-concept exploit code, all in about two hours.
Argus discovered and successfully reproduced the flaw on July 30, and researchers shared the full details with the vendor on August 5. ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday.
Update 08/27 – Removed incorrect claim that the usable set of sites is less than the total number of Avada installations after receiving clarification from the Wordfence team that the two plugins are automatically installed together.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

