Description
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Avada theme for WordPress and its Fusion Builder plugin suffer an arbitrary file write vulnerability. The flaw allows an attacker who can access the site to upload arbitrary PHP files, enabling full remote code execution and compromise of the entire WordPress installation. The vulnerability exists in all Avada releases up to and including version 7.16 when the Fusion Builder plugin is installed and active in any version up to and including 3.16. An attacker must have no authentication and must trigger the write vector while the site contains administrator‑created content, but no special host‑break privileges are needed.

Affected Systems

Vulnerable systems are those running ThemeFusion Avada theme version 7.16 or older together with Fusion Builder plugin version 3.16 or older. Any WordPress site that has both components installed and active is at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating critical severity. EPSS information is currently unavailable, and the flaw is not listed in CISA's KEV catalog. The likely attack path requires an unauthenticated attacker to send requests to the site’s execution endpoint that is exposed through the theme and plugin, with the precondition that administrative content exists to satisfy the hidden prerequisite. Successful exploitation leads to immediate compromise of the site with no user interaction beyond web access.

Generated by OpenCVE AI on August 26, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Avada theme to version 7.17 or newer.
  • Update the Fusion Builder plugin to version 3.17 or newer.
  • If an immediate upgrade is not possible, temporarily disable or remove the Fusion Builder plugin until the update is applied.

Generated by OpenCVE AI on August 26, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.
Title Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-26T06:08:28.442Z

Reserved: 2026-07-30T19:46:51.827Z

Link: CVE-2026-18431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-26T07:16:45.500

Modified: 2026-08-26T16:19:05.917

Link: CVE-2026-18431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:30:16Z

Weaknesses