Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-18431

Avada Theme / Fusion Builder unauthenticated RCE chain

A six-flaw exploit chain in ThemeFusion's Avada theme and Fusion Builder plugin lets unauthenticated attackers execute arbitrary PHP on the server. CVSS 9.8 Critical. Patch to Avada 7.16.1 and Fusion Builder 3.16.1.

cat cve-2026-18431.json
Vendor
ThemeFusion
Product
Avada WordPress theme (≤ 7.16) and Fusion Builder plugin (≤ 3.16)
CVSS
9.8
EPSS (exploit probability)
0.6%
Status
patched
Published

ThemeFusion’s flagship WordPress theme Avada and its companion Fusion Builder plugin carry a six-vulnerability chain (CVE-2026-18431, CVSS 9.8) that allows unauthenticated remote code execution. Exploitation requires both products to be active simultaneously — the chain combines an authorization bypass, an input-validation flaw, a trust-boundary violation, and a file-handling restriction bypass to land arbitrary PHP code on the server.

Affected versions: Avada ≤ 7.16 and Fusion Builder ≤ 3.16 when both are active.

Fixed versions: Avada 7.16.1 and Fusion Builder 3.16.1, released August 26, 2026.

No known active exploitation has been reported at the time of disclosure, but CVSS 9.8 unauthenticated RCE on a widely deployed theme is a high-value target.

Recommended action: Update both components immediately. WordPress sites running Avada without Fusion Builder active are not vulnerable to this specific chain, but updating either way closes the individual flaws.