A critical unauthenticated remote-code-execution vulnerability, CVE-2026-18431 (CVSS 9.8), affects the Avada WordPress theme through version 7.16 when its bundled Fusion Builder plugin through version 3.16 is installed and active. The six-stage exploit chain combines authorization, trust-boundary, input-validation, and file-handling flaws, enabling remote attackers to write and execute arbitrary PHP files and potentially take full control of vulnerable WordPress sites; exploitation also requires certain administrator-authored content.
ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1. Wordfence reported that its Argus agent discovered and reproduced the chain and produced a proof of concept, which Wordfence validated in an isolated environment; firewall protection was made available to paid customers before the public disclosure and was scheduled for free users. No public exploit or CISA Known Exploited Vulnerabilities listing had been reported at publication.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
ThemeFusion publicly released Avada 7.16.1 and Fusion Builder 3.16.1, which fully address the six weaknesses comprising CVE-2026-18431.
ThemeFusion provided pre-release patched packages for Avada and Fusion Builder to Wordfence for review.
ThemeFusion acknowledged Wordfence's report concerning CVE-2026-18431.
Wordfence submitted full technical details of the Avada and Fusion Builder vulnerability chain to ThemeFusion through its Vulnerability Management Portal.
Wordfence provided Premium, Care, and Response customers a firewall rule covering known exploitation techniques for CVE-2026-18431.
Wordfence Argus discovered and reproduced CVE-2026-18431, a six-step unauthenticated file-write chain in Avada and Fusion Builder that can enable arbitrary PHP execution. Wordfence validated the proof of concept in an isolated environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesocradar.io
Open sourcebleepingcomputer.com
Open sourcethreataft.com
Open sourcemalware.news
Open sourceavada.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.