Avada/Fusion Builder zero-click RCE (CVE-2026-18431)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that enables unauthenticated arbitrary PHP code execution on affected WordPress servers. It affects Avada up to 7.16 and Fusion Builder up to 3.16, limiting exposure to sites running both vulnerable components. ThemeFusion has released fixes in Avada 7.16.1 and Fusion Builder 3.16.1. Successful exploitation can lead to full website compromise.
Related Happenings
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation Wave
H score53
First: 18.02.2026 08:52
Last: 18.02.2026 08:52
Sources 1
About this happening:
CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation WaveAbout this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
Timeline
-
27.08.2026 00:33 1 articles · 1h ago
Argus reproduces the CVE-2026-18431 chain
Technical Analysis UpdateArgus found and successfully reproduced the six-step CVE-2026-18431 vulnerability chain on July 30, confirming a path that can end in arbitrary PHP code execution on a target server when vulnerable Avada and Fusion Builder components are present.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 1h ago
Wordfence shares full CVE-2026-18431 details with ThemeFusion
Initial DisclosureOn August 5, the researchers shared the full details of CVE-2026-18431 to ThemeFusion after reproducing the flaw and developing proof-of-concept exploit code.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 1h ago
ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes
Mitigation Patch UpdateThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25, addressing the vulnerable versions that researchers said were affected by CVE-2026-18431.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 2 articles · 1h ago
Wordfence publicly details the CVE-2026-18431 zero-click RCE chain
Initial DisclosureOn 2026-08-26, Wordfence publicly described CVE-2026-18431 as a zero-click chain of six security issues with a 9.8 critical severity that lets an unauthenticated attacker trigger arbitrary PHP code execution on affected Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33