A critical vulnerability chain in the popular Avada theme for WordPress can let an unauthenticated attacker execute arbitrary PHP code on a server, according to researchers at Defiant’s Wordfence team. The exploit combines six security issues into a zero-click attack, meaning no user interaction is required. The flaws are collectively tracked as CVE-2026-18431 and carry a severity score of 9.8, which is considered critical. The attack relies on exploiting authorization, input-validation, trust-boundary, and file-handling weaknesses in a specific order to achieve remote code execution.

Hackers who successfully exploit the vulnerability could fully compromise a website, potentially planting malware, accessing databases, redirecting visitors to malicious sites, or adding rogue admin accounts. The issue affects Avada versions up to 7.16 and the Fusion Builder plugin versions up to 3.16, the Wordfence researchers reported on Tuesday. ThemeFusion, the developer behind both products, has fixed the issue, but Wordfence is withholding full technical details to give administrators time to install updates. The researchers provided only a general overview of the attack chain to avoid tipping off would-be attackers.

While exploitation requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target site, Wordfence clarified that Fusion Builder is a required plugin for the Avada theme. This means every site running the Avada theme also runs the Fusion Builder plugin. Avada is a very popular product with more than one million sales, so the prerequisites do not narrow the pool of potential targets. As the researchers put it, any site with the Avada theme installed is going to be exploitable.

Wordfence discovered the six-step vulnerability chain using an internal agentic framework called Argus, which also developed proof-of-concept exploit code. The discovery and reproduction of the flaw took about two hours. The researchers shared full details with ThemeFusion on August 5, after finding and reproducing the issue on July 30. ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 the day before the report was published.

Wordfence later clarified that because the Avada theme installs together with Fusion Builder, any site running an outdated version of the theme can be compromised by exploiting CVE-2026-18431. Administrators using Avada are urged to update their theme and plugin to the latest versions to secure their sites. The vulnerability is notable for its zero-click nature and the widespread use of the theme, which increases the potential attack surface across WordPress installations in the US and globally.

More cybersecurity news from TechManNews.