ThemeFusion patches critical Avada and Fusion Builder flaw CVE-2026-18431 that allows zero-click remote code execution on WordPress sites

A critical flaw in the Avada WordPress theme can let an outsider take over a website without logging in or tricking a user to click anything. ThemeFusion fixed the issue as CVE-2026-18431 in Avada 7.16.1 and Fusion Builder 3.16.1; the attack chains six bugs to achieve unauthenticated remote code execution, meaning attackers can run PHP code on the server. A vulnerable site must be running both Avada up to 7.16 and Fusion Builder up to 3.16.
Why it matters: Websites using Avada and Fusion Builder could be fully compromised for malware delivery, data theft, redirects, or rogue admin creation. Organizations and site owners running these products should update immediately to the fixed versions and verify both components are patched.

Sources

Critical Avada WordPress theme flaw enables zero-click RCE
Bill Toulas 2026.08.26 100% relevant
This article appears to be the first tracked item here establishing the specific CVE-2026-18431 Avada/Fusion Builder remote-code-execution event and the vendor's release of fixed versions.
← Back to all stories