CRITICAL
9.8 CVE-2026-18431 Published 26 Aug 2026
Avada WordPress Theme Arbitrary File Write
Worried this affects one of your servers?
The Avada theme for WordPress is vulnerable to Arbitrary File Write when used with the Fusion Builder plugin.
Attackers can exploit this vulnerability to write and execute arbitrary PHP files, leading to remote code execution and complete site compromise.
This issue affects Avada versions up to 7.16 and Fusion Builder versions up to 3.16. Successful exploitation requires both plugins to be installed and active, as well as specific administrator-authored content.
Reference: CVE-2026-18431 on NVD
← Back to Security News