Avada WordPress Theme Patches Critical Zero-Click RCE
ThemeFusion patches a six-flaw chain in Avada and Fusion Builder that lets unauthenticated attackers execute arbitrary PHP code. CVSS 9.8 Critical.

ThemeFusion has patched a critical vulnerability chain in its Avada WordPress theme and Fusion Builder plugin that allows unauthenticated attackers to execute arbitrary PHP code on the server. No login, no privileges, no user interaction required.
The flaw is tracked as CVE-2026-18431 with a CVSS score of 9.8. It was discovered by researchers using an AI-assisted framework called Argus and reported by BleepingComputer on August 26, 2026.
What the flaw is
The vulnerability isn’t a single bug — it’s a six-step chain spanning both products: an authorization bypass, an input-validation flaw, a trust-boundary violation, and a file-handling restriction bypass that together culminate in remote code execution. Successful exploitation requires both Avada and Fusion Builder to be active on the same site. Neither component alone closes the full chain; you need to patch both.
Vulnerability class: Chained authorization bypass + input validation + file upload restriction bypass leading to PHP RCE.
Attack vector: Network, unauthenticated, no user interaction.
CVSS: 9.8 Critical.
What’s patched
ThemeFusion released fixes in:
- Avada 7.16.1
- Fusion Builder 3.16.1
Both updates were released August 26, 2026. No known active exploitation has been reported at time of disclosure.
What to do
Update both plugins now. If you’re running WordPress auto-updates, confirm both updates applied — Avada (theme) and Fusion Builder (plugin) are separate update targets and can slip through if only one is configured for auto-update.
Sites running Avada without Fusion Builder active are not vulnerable to this specific RCE chain, but the individual component flaws still exist in unpatched versions. Update regardless.
Priority call: patch this before anything else on your WordPress queue today. CVSS 9.8, unauthenticated, RCE — this is the kind of bug that gets weaponized within days of a public disclosure. The research chain is already documented; weaponization is a matter of time.
Related coverage: miniOrange SAML WordPress Flaws Under Active Exploit · Forminator Plugin RCE Flaw Hits 600K Sites · Critical Auth Bypass Hits WordPress Plugins
- [ CRITICAL ]CVE-2026-18431Avada Theme / Fusion Builder unauthenticated RCE chain
Found this useful? Share it.


