CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5814

As cited

Copy frozen at (site build).

vulnerabilities

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

Wordfence's artificial intelligence (AI) research agent Argus discovered a critical six-step remote code execution vulnerability chain in the Avada WordPress theme (over 1 million sales) and Fusion Builder plugin that allows unauthenticated attackers to write arbitrary PHP files and achieve complete site compromise. The vulnerability, tracked as CVE-2026-18431 with a CVSS score of 9.8, affects Avada versions up to 7.16 and Fusion Builder up to 3.16. ThemeFusion released patches on August 25, 2026, with Wordfence Premium customers receiving firewall protection on July 30, 2026, and free users protected starting August 29, 2026.

Why it matters: WordPress site operators using Avada with Fusion Builder must update to patched versions (7.16.1 and 3.16.1 respectively) immediately, as this unauthenticated RCE allows complete server compromise without user interaction.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

Wordfence's artificial intelligence (AI) research agent Argus discovered a critical six-step remote code execution vulnerability chain in the Avada WordPress theme (over 1 million sales) and Fusion Builder plugin that allows unauthenticated attackers to write arbitrary PHP files and achieve complete site compromise. The vulnerability, tracked as CVE-2026-18431 with a CVSS score of 9.8, affects Avada versions up to 7.16 and Fusion Builder up to 3.16. ThemeFusion released patches on August 25, 2026, with Wordfence Premium customers receiving firewall protection on July 30, 2026, and free users protected starting August 29, 2026.

Why it matters: WordPress site operators using Avada with Fusion Builder must update to patched versions (7.16.1 and 3.16.1 respectively) immediately, as this unauthenticated RCE allows complete server compromise without user interaction.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary