Impact
Avada theme for WordPress and its Fusion Builder plugin suffer an arbitrary file write vulnerability. The flaw allows an attacker who can access the site to upload arbitrary PHP files, enabling full remote code execution and compromise of the entire WordPress installation. The vulnerability exists in all Avada releases up to and including version 7.16 when the Fusion Builder plugin is installed and active in any version up to and including 3.16. An attacker must have no authentication and must trigger the write vector while the site contains administrator‑created content, but no special host‑break privileges are needed.
Affected Systems
Vulnerable systems are those running ThemeFusion Avada theme version 7.16 or older together with Fusion Builder plugin version 3.16 or older. Any WordPress site that has both components installed and active is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. EPSS information is currently unavailable, and the flaw is not listed in CISA's KEV catalog. The likely attack path requires an unauthenticated attacker to send requests to the site’s execution endpoint that is exposed through the theme and plugin, with the precondition that administrative content exists to satisfy the hidden prerequisite. Successful exploitation leads to immediate compromise of the site with no user interaction beyond web access.
OpenCVE Enrichment