A critical vulnerability (CVE-2026-18431) affects the Avada theme for WordPress in versions up to and including 7.16, when used in conjunction with the Fusion Builder plugin (versions up to and including 3.16). The flaw stems from a chain of authorization and input validation weaknesses across both components, allowing unauthenticated attackers to write arbitrary files to the server. Successful exploitation enables the creation and execution of arbitrary PHP files, leading to remote code execution (RCE) and complete site compromise. Exploitation requires both Avada and Fusion Builder to be installed and active, along with certain administrator-authored content being present on the site. The vulnerability is classified as high severity due to its unauthenticated attack vector and potential for full system compromise. Users are advised to update to patched versions of both the Avada theme and Fusion Builder plugin immediately.