← Back to overview

CVE-2026-18431 affects the Avada theme for WordPress in versions up to and including 7.16, when the Fusion Builder plugin (up to version 3.16) is installed and active. A chain of authorization and input validation weaknesses allows unauthenticated attackers to write arbitrary files to the server. Exploitation can lead to creation and execution of arbitrary PHP files, resulting in remote code execution and complete site compromise. The vulnerability requires both Avada and Fusion Builder to be installed and active, along with certain administrator-authored content. This is a critical unauthenticated RCE vulnerability affecting a widely-used WordPress theme and its companion plugin.

Affected products

  • Avada WordPress Theme (up to 7.16)
  • Fusion Builder Plugin (up to 3.16)

Related CVE's

  • CVE-2026-18431

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities