CVE Tools

Critical Avada WordPress theme flaw enables zero-click RCE

BleepingComputerBy Bill Toulas

PoC publicAvadaFusion Builder

Our summary

Researchers at Wordfence have disclosed a critical vulnerability chain, tracked as CVE-2026-18431, that allows unauthenticated attackers to execute arbitrary PHP code on websites using the Avada theme and Fusion Builder plugin. With a CVSS score of 9.8, this zero-click exploit combines six distinct security flaws to compromise the server, enabling actions such as database access or the creation of rogue administrator accounts. A proof-of-concept exploit is now available following discovery by Wordfence’s agentic framework, Argus. ThemeFusion has addressed the issue in recent updates; administrators should immediately upgrade to Avada 7.16.1 and Fusion Builder 3.16.1 to mitigate the risk.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store