Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks

A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A WordPress dashboard displaying the Avada theme interface, with a security vulnerability warning overlay showing code injection and unauthorized access pathway
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Wordfence disclosed a critical flaw chain in the Avada WordPress theme and Fusion Builder plugin, tracked as CVE-2026-18431, carrying a severity score of 9.8 out of 10.
  • The bug lets an attacker who has never logged in run arbitrary PHP code on the web server, with no user interaction required.
  • Avada versions up to 7.16 and Fusion Builder versions up to 3.16 are vulnerable; ThemeFusion shipped fixes in 7.16.1 and 3.16.1.
  • Exploitation requires both the vulnerable theme and the vulnerable plugin to be active, which narrows the pool of at-risk sites from Avada's million-plus buyers.
  • Wordfence found the chain using an in-house AI tool called Argus, which wrote working exploit code in around two hours.

A newly disclosed flaw in one of the web's best-selling WordPress themes can hand a stranger on the internet complete control of a site, without any user doing a thing.

Researchers at Defiant's Wordfence team say the bug chain sits inside the Avada theme and its companion Fusion Builder plugin, both made by ThemeFusion. Avada alone has sold more than a million copies.

The issue is tracked as CVE-2026-18431 and rated 9.8 out of 10 for severity. About as bad as a web flaw gets.

What can attackers actually do?

They can run their own PHP code on the server hosting the website. That's remote code execution, and it's the outcome defenders dread most.

From there, criminals can plant malware, read the site's database, add themselves as administrators, or redirect visitors to scam pages. The site owner may not notice for weeks.

Because the attack requires zero clicks, no admin has to open a booby-trapped email or follow a bad link. The attacker just sends web requests to the vulnerable site.

How the attack works, in plain English

Wordfence is holding back technical detail on purpose, to give site owners time to patch. What they've shared is the shape of the chain: six weaknesses, exploited in a specific order.

The attacker feeds input through a public part of the site, then tricks the software into treating it as if it came from a trusted, logged-in user. Each step alone is minor. Chained, they end with the attacker writing a file to a location they should never reach.

One important caveat: both the vulnerable Avada theme and the vulnerable Fusion Builder plugin must be active on the target site. Sites running only one, or a patched version, aren't exposed.

The Elementor Pro flaw we reported on 20 August followed the same basic mechanism, a chained path to remote file write, which suggests this class of attack is finding new homes in premium WordPress products.

Who found it, and when was it fixed?

Argus, Wordfence's internal AI framework, found the chain and produced working exploit code on July 30. The researchers reported it privately to ThemeFusion on August 5. ThemeFusion acknowledged on August 10 and released patches the day before Wordfence went public.

Item Detail
CVE CVE-2026-18431
Severity 9.8 (critical)
Vulnerable Avada up to 7.16
Vulnerable Fusion Builder up to 3.16
Fixed in Avada 7.16.1, Fusion Builder 3.16.1
Disclosed November 2025

What should site owners do right now?

Update Avada to 7.16.1 and Fusion Builder to 3.16.1 today. If an agency runs your site, ask them to confirm both versions in writing.

After updating, check the site's administrator list for unfamiliar names and review recently uploaded files in the WordPress uploads folder. Those are the two places attackers typically leave a foothold.

Ordinary visitors don't need to act. If a site you use starts redirecting you or demanding logins in unusual places, close the tab and tell the site owner.

© 2026 Threat Vectr