Mobble
Technology · Cybersecurity · published 2026-08-26 · via BleepingComputer

WordPress Avada theme chain allows unauthenticated code execution

A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code. The flaws, tracked as CVE-2026-18431 with a critical severity score of 9.8, affect Avada up to 7.16 and Fusion Builder up to 3.16. Wordfence discovered the issue using its Argus framework, and fixes are available in versions 7.16.1 and 3.16.1.

Read the full article at BleepingComputer →
Related stories
CISA warns of active exploitation of critical Gitea code injection vulnerability · Cybersecurity
WordPress miniOrange plugin flaws exploited for admin account takeover · Cybersecurity
Calix router vulnerability enables unauthenticated remote port mapping · Cybersecurity
SharePoint RCE chain exploited in the wild after PoC release · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Critical Avada WordPress theme flaw enables zero-click RCE.” Browse more stories.