Avada/Fusion Builder zero-click RCE (CVE-2026-18431)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-18431 is a critical 9.8 vulnerability chain in Avada and Fusion Builder that lets an unauthenticated attacker trigger arbitrary PHP code execution and complete site compromise on affected WordPress servers. The flaw affects Avada up to 7.16 and Fusion Builder up to 3.16, with exposure limited to sites running both vulnerable components. Argus reproduced the six-step chain on July 30, Wordfence publicly detailed it on 2026-08-26, and ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25. The disclosed chain can also support malware planting, database access, rogue admin accounts, and malicious redirects on vulnerable sites.
Related Happenings
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation Wave
H score53
First: 18.02.2026 08:52
Last: 18.02.2026 08:52
Sources 1
About this happening:
CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation WaveAbout this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
Timeline
-
27.08.2026 00:33 1 articles · 14d ago
Argus reproduces the CVE-2026-18431 chain
Technical Analysis UpdateArgus found and successfully reproduced the six-step CVE-2026-18431 vulnerability chain on July 30, confirming a path that can end in arbitrary PHP code execution on a target server when vulnerable Avada and Fusion Builder components are present.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 14d ago
Wordfence shares full CVE-2026-18431 details with ThemeFusion
Initial DisclosureOn August 5, the researchers shared the full details of CVE-2026-18431 to ThemeFusion after reproducing the flaw and developing proof-of-concept exploit code.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 14d ago
ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes
Mitigation Patch UpdateThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 on August 25, addressing the vulnerable versions that researchers said were affected by CVE-2026-18431.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 3 articles · 14d ago
Wordfence publicly details the CVE-2026-18431 zero-click RCE chain
Initial DisclosureOn 2026-08-26, Wordfence publicly described CVE-2026-18431 as a zero-click chain of six security issues with a 9.8 critical severity that lets an unauthenticated attacker trigger arbitrary PHP code execution on affected Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE — thehackernews.com — 29.08.2026 19:25