CVE-2026-18431 affects the Avada theme for WordPress in versions up to and including 7.16, when the Fusion Builder plugin (up to version 3.16) is installed and active. A chain of authorization and input validation weaknesses allows unauthenticated attackers to write arbitrary files to the server. Exploitation can lead to creation and execution of arbitrary PHP files, resulting in remote code execution and complete site compromise. The vulnerability requires both Avada and Fusion Builder to be installed and active, along with certain administrator-authored content. This is a critical unauthenticated RCE vulnerability affecting a widely-used WordPress theme and its companion plugin.