Find notable cyber news and cases, enriched with sources, timelines, and signals.

Avada/Fusion Builder zero-click RCE (CVE-2026-18431)

Vulnerability
First reported
Last updated
Happening score
H score 44
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that lets an unauthenticated attacker trigger arbitrary PHP code execution and complete site compromise on affected WordPress servers. The flaw affects Avada up to 7.16 and Fusion Builder up to 3.16, with exposure limited to sites running both vulnerable components. Argus reproduced the six-step chain on July 30, Wordfence publicly detailed it on 2026-08-26, and ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. The disclosed chain can also support malware planting, database access, rogue admin accounts, and malicious redirects on vulnerable sites.

Related Happenings

CISA KEV multi-product active exploitation wave (CVE-2020-7796)

Exploitation Wave
H score53 First: 18.02.2026 08:52 Last: 18.02.2026 08:52 Sources 1

About this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...

Timeline

  1. 27.08.2026 00:33 1 articles · 14d ago

    Argus reproduces the CVE-2026-18431 chain

    Technical Analysis Update

    Argus found and successfully reproduced the six-step CVE-2026-18431 vulnerability chain on July 30, confirming a path that can end in arbitrary PHP code execution on a target server when vulnerable Avada and Fusion Builder components are present.

    Show sources
  2. 27.08.2026 00:33 1 articles · 14d ago

    Wordfence shares full CVE-2026-18431 details with ThemeFusion

    Initial Disclosure

    On August 5, the researchers shared the full details of CVE-2026-18431 to ThemeFusion after reproducing the flaw and developing proof-of-concept exploit code.

    Show sources
  3. 27.08.2026 00:33 1 articles · 14d ago

    ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes

    Mitigation Patch Update

    ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25, addressing the vulnerable versions that researchers said were affected by CVE-2026-18431.

    Show sources
  4. 27.08.2026 00:33 3 articles · 14d ago

    Wordfence publicly details the CVE-2026-18431 zero-click RCE chain

    Initial Disclosure

    On 2026-08-26, Wordfence publicly described CVE-2026-18431 as a zero-click chain of six security issues with a 9.8 critical severity that lets an unauthenticated attacker trigger arbitrary PHP code execution on affected Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

    Show sources