๐Ÿ” CVE Alert

CVE-2026-18431

CRITICAL 9.8

Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.

CWE CWE-862
Vendor themefusion
Product avada (fusion) builder
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for themefusion avada (fusion) builder

Be the first to know when new critical vulnerabilities affecting themefusion avada (fusion) builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

themefusion / Avada (Fusion) Builder
0 โ‰ค 3.16
ThemeFusion / Avada | Website Builder For WordPress & WooCommerce
0 โ‰ค 7.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390?source=cve avada.com: https://avada.com/documentation/avada-changelog/

Credits

Alex Thomas Wordfence Argus