PT-2026-81951 · WordPress+1 · Fusion Builder+1

·

CVE-2026-18431

·

Published

2026-08-26

·

Updated

2026-08-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avada versions prior to 7.16.1 Fusion Builder versions prior to 3.16.1
Description An unauthenticated attacker can achieve remote code execution and complete site compromise by writing attacker-controlled PHP files to the server. This is possible through a six-stage chain of weaknesses involving authorization, input validation, trust boundaries, privileged behavior, and file handling across the theme and its required plugin. Successful exploitation requires both the theme and the plugin to be installed and active, as well as the presence of certain administrator-authored content. Over 1 million sites are potentially affected.
Recommendations Update Avada to version 7.16.1 or later. Update Fusion Builder to version 3.16.1 or later.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18431

Affected Products

Avada
Fusion Builder