As cited
Copy frozen at (site build).
vulnerabilities
Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
Wordfence's artificial intelligence (AI) research agent Argus discovered a critical six-step remote code execution vulnerability chain in the Avada WordPress theme (over 1 million sales) and Fusion Builder plugin that allows unauthenticated attackers to write arbitrary PHP files and achieve complete site compromise. The vulnerability, tracked as CVE-2026-18431 with a CVSS score of 9.8, affects Avada versions up to 7.16 and Fusion Builder up to 3.16. ThemeFusion released patches on August 25, 2026, with Wordfence Premium customers receiving firewall protection on July 30, 2026, and free users protected starting August 29, 2026.
Why it matters: WordPress site operators using Avada with Fusion Builder must update to patched versions (7.16.1 and 3.16.1 respectively) immediately, as this unauthenticated RCE allows complete server compromise without user interaction.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
Wordfence's artificial intelligence (AI) research agent Argus discovered a critical six-step remote code execution vulnerability chain in the Avada WordPress theme (over 1 million sales) and Fusion Builder plugin that allows unauthenticated attackers to write arbitrary PHP files and achieve complete site compromise. The vulnerability, tracked as CVE-2026-18431 with a CVSS score of 9.8, affects Avada versions up to 7.16 and Fusion Builder up to 3.16. ThemeFusion released patches on August 25, 2026, with Wordfence Premium customers receiving firewall protection on July 30, 2026, and free users protected starting August 29, 2026.
Why it matters: WordPress site operators using Avada with Fusion Builder must update to patched versions (7.16.1 and 3.16.1 respectively) immediately, as this unauthenticated RCE allows complete server compromise without user interaction.
- Source published
- First seen by Cybersecurity Tracker