A critical vulnerability chain in the popular Avada WordPress theme could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable websites without any user interaction.
Tracked as CVE-2026-18431, the flaw has received a critical CVSS score of 9.8. Researchers from Defiant’s Wordfence team say the attack combines six separate security weaknesses into a zero-click exploit that must be triggered in a specific sequence.
The vulnerabilities involve authorization, input validation, trust boundaries and file handling. When chained together, they can allow an attacker to move from publicly controlled input to privileged functionality and ultimately execute PHP code on the targeted server.
A successful attack could give hackers extensive control over an affected website. They could potentially install malware, access databases, create unauthorized administrator accounts or redirect visitors to malicious websites.
CVE-2026-18431 affects Avada versions through 7.16 and Fusion Builder versions through 3.16. However, Wordfence said exploitation requires both the vulnerable Avada theme and vulnerable Fusion Builder plugin to be active on the same website.
Wordfence has not released the complete technical details of the exploit chain to give website administrators time to apply the available security updates. The researchers described the attack as beginning with attacker-controlled input exposed through a public request, followed by access to functionality normally restricted from unauthenticated users.
The chain then invokes a privileged component outside its intended context and uses request data to influence trusted application state. This leads to an inadequately protected administrative operation before the final stage bypasses file-handling restrictions governing what files can be written and where they can be placed.
Despite Avada’s popularity, the requirement for both vulnerable components to be installed and active considerably reduces the number of websites exposed to the complete attack.
The discovery also highlights the growing role of AI-powered security research. Wordfence found the vulnerability using its internal agentic security framework, Argus, which also generated proof-of-concept exploit code. The entire discovery and reproduction process reportedly took about two hours.
Argus identified and successfully reproduced the vulnerability on July 30. Wordfence provided the full findings to ThemeFusion on August 5, and the developer acknowledged the report on August 10.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
ThemeFusion has now released security fixes in Avada 7.16.1 and Fusion Builder 3.16.1. Administrators using Avada should update both the theme and Fusion Builder plugin to the latest versions to address the vulnerability.
Critical Avada WordPress Flaw Enables Zero-Click Remote Code Execution





