Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution
A critical Avada WordPress vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. The exploit chains six security issues into a zero-click attack, collectively tracked as CVE-2026-18431 and assigned a 9.8 critical severity score.
How the Avada WordPress Vulnerability Works
The attack comprises exploits for authorization, input-validation, trust-boundary, and file-handling weaknesses, which must be executed in a specific order to enable arbitrary PHP code execution on a target server. Hackers who successfully exploit these vulnerabilities could fully compromise websites for malicious activities ranging from planting malware and accessing databases to redirecting visitors to malicious sites or adding rogue admin accounts.

The Avada WordPress vulnerability affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16, according to researchers at Defiant’s Wordfence team. Exploitation requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target website. Since Fusion Builder is a required plugin for the Avada theme, all sites running Avada are also running Fusion Builder, making the pool of potential targets substantial.
Scale of the Threat and Remediation
The Avada theme is quite popular, with more than 1 million sales, so the Avada WordPress vulnerability threatens a sizable pool of sites. ThemeFusion, the developer behind both products, has already fixed the issue. Wordfence discovered the six-step vulnerability chain using an internal agentic framework called Argus, which also developed proof-of-concept exploit code in about two hours. Argus found and successfully reproduced the flaw on July 30, and the researchers shared full details to the vendor on August 5. ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1.
While ThemeFusion has patched the vulnerability, Wordfence is not sharing complete technical details to give administrators sufficient time to install the latest updates. Site owners running Avada should update to the patched versions immediately. This incident underscores the ongoing security challenges facing WordPress ecosystems, as covered earlier when Meta to Pay $18 Billion to Settle Lawsuit Over Teen Safety Concerns highlighted broader platform safety concerns. In a related development, Meta settles major teen safety lawsuit with 29 US states demonstrated the scale of vulnerabilities affecting WordPress users and their administrators.
المصدر: BleepingComputer