Find notable cyber news and cases, enriched with sources, timelines, and signals.

Avada/Fusion Builder zero-click RCE (CVE-2026-18431)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that enables unauthenticated arbitrary PHP code execution on affected WordPress servers. It affects Avada up to 7.16 and Fusion Builder up to 3.16, limiting exposure to sites running both vulnerable components. ThemeFusion has released fixes in Avada 7.16.1 and Fusion Builder 3.16.1. Successful exploitation can lead to full website compromise.

Related Happenings

CISA KEV multi-product active exploitation wave (CVE-2020-7796)

Exploitation Wave
H score53 First: 18.02.2026 08:52 Last: 18.02.2026 08:52 Sources 1

About this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...

Timeline

  1. 27.08.2026 00:33 1 articles · 1h ago

    Argus reproduces the CVE-2026-18431 chain

    Technical Analysis Update

    Argus found and successfully reproduced the six-step CVE-2026-18431 vulnerability chain on July 30, confirming a path that can end in arbitrary PHP code execution on a target server when vulnerable Avada and Fusion Builder components are present.

    Show sources
  2. 27.08.2026 00:33 1 articles · 1h ago

    Wordfence shares full CVE-2026-18431 details with ThemeFusion

    Initial Disclosure

    On August 5, the researchers shared the full details of CVE-2026-18431 to ThemeFusion after reproducing the flaw and developing proof-of-concept exploit code.

    Show sources
  3. 27.08.2026 00:33 1 articles · 1h ago

    ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes

    Mitigation Patch Update

    ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25, addressing the vulnerable versions that researchers said were affected by CVE-2026-18431.

    Show sources
  4. 27.08.2026 00:33 2 articles · 1h ago

    Wordfence publicly details the CVE-2026-18431 zero-click RCE chain

    Initial Disclosure

    On 2026-08-26, Wordfence publicly described CVE-2026-18431 as a zero-click chain of six security issues with a 9.8 critical severity that lets an unauthenticated attacker trigger arbitrary PHP code execution on affected Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

    Show sources