A critical vulnerability chain has been discovered in the Avada WordPress theme, one of the most popular commercial WordPress themes. The flaw allows unauthenticated attackers to execute arbitrary PHP code on the server without any user interaction, qualifying it as a zero-click remote code execution (RCE) vulnerability. The attack requires no authentication, significantly raising its risk level and potential for mass exploitation. WordPress sites using the Avada theme are at risk of full server compromise. The vulnerability chain suggests multiple flaws are combined to achieve code execution. Site administrators using Avada are strongly urged to apply patches or mitigations immediately. The critical nature of this vulnerability, combined with the wide adoption of the Avada theme, could expose a large number of websites to attack.