CVE-2026-18431 (matched: wordpress)

  • Wednesday, 26th August, 2026
  • 22:08pm

A security flaw has been identified in the Avada theme for WordPress, a popular tool used to build and customize WordPress websites. This issue only affects sites running Avada version 7.16 or older, paired with the Fusion Builder plugin (version 3.16 or older) that is both installed and active on the site.

For this flaw to be successfully exploited, specific content created by a site administrator must already exist on the affected site. If taken advantage of, unauthenticated attackers (meaning they do not need your site’s login credentials) can write their own controlled files to your website’s server. This can be used to run any code of their choosing on your site, leading to full compromise of your WordPress site and all its stored content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18431

« Back