A security flaw has been identified in the Avada WordPress theme and its companion Fusion Builder plugin. The issue impacts all versions of Avada up to and including 7.16, as well as all versions of Fusion Builder up to and including 3.16.
This vulnerability allows unauthenticated attackers (people who do not have login access to your website) to write their own custom files to your site's server. If exploited, this can be used to upload and run harmful code, giving the attacker full control of your site. This includes the ability to steal visitor or business data, alter your site's content, or take over your website entirely.
For this flaw to be successfully exploited, both the Avada theme and Fusion Builder plugin must be installed and active on your WordPress site, along with specific content created by a site administrator.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18431