CVE-2026-18431 (matched: php)

  • Thursday, 27th August, 2026
  • 04:08am

A security vulnerability impacts the Avada WordPress theme (all versions up to and including 7.16) when the companion Fusion Builder plugin (all versions up to and including 3.16) is also installed and active on your site.

The flaw is caused by gaps in permission checks and input validation between the two tools, which allows unauthenticated attackers (people who do not have approved access to your site) to write their own custom files to your web server.

If exploited, this can let attackers create and run malicious code on your site, leading to full compromise and take over of your entire website. For this flaw to be successfully exploited, both Avada and Fusion Builder must be active on your site, and specific content created by your site administrator must already be present.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18431

« Back