WordPress Avada theme chain allows unauthenticated code execution
A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code. The flaws, tracked as CVE-2026-18431 with a critical severity score of 9.8, affect Avada up to 7.16 and Fusion Builder up to 3.16. Wordfence discovered the issue using its Argus framework, and fixes are available in versions 7.16.1 and 3.16.1.
Related stories
SharePoint RCE chain exploited in the wild after PoC release · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source.
Original headline: “Critical Avada WordPress theme flaw enables zero-click RCE.” Browse more stories.