A security flaw has been identified in the Avada WordPress theme and its companion Fusion Builder plugin, if you use both tools on your website. The issue impacts all versions of Avada up to and including version 7.16, and all versions of Fusion Builder up to and including version 3.16.
This weakness allows attackers who do not have any login access to your site to write their own malicious files to your web server. If exploited, this can let attackers run harmful code directly on your site, which may lead to your entire website being taken over and fully compromised.
For this vulnerability to be successfully exploited, both the Avada theme and Fusion Builder plugin must be installed and active on your site, and specific content created by your site’s administrators must also be present.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18431