Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Six bugs, one order of operations: Avada's zero-click chain is a same-day patch

Wordfence says CVE-2026-18431 lets an unauthenticated attacker run PHP on sites running both a vulnerable Avada theme and Fusion Builder. Updating either component breaks the chain.

The Watch · Security desk

How we use AISend a correction

What happened

  • Wordfence says six chained flaws in the Avada WordPress theme allow unauthenticated arbitrary PHP execution, tracked together as CVE-2026-18431 at 9.8 severity.
  • ThemeFusion shipped Avada 7.16.1 and Fusion Builder 3.16.1 the day before the advisory went out.
  • Wordfence says the attack only works where vulnerable versions of both the theme and the plugin are active.

Why it matters

  • decision Teams with a slow theme pipeline are not blocked: whichever of the two updates clears change control first is enough to break the sequence, which turns one urgent decision into two ordinary ones.
  • exposure Nothing has to be phished or clicked, so who is reachable is decided purely by installed versions and internet exposure, and any site already hit needs cleanup that an update does not perform.
  • constraint With the technical detail withheld, defenders have no request signature to search logs for, so version inventory is the only verification available to them.
  • precedent A chain built in hours against a vendor confirmation measured in days sets the expectation that patch windows will be sized by automated discovery rather than by researcher backlog.

The prerequisite sitting in the middle of Wordfence's advisory is the useful part. Exploitation needs a vulnerable Avada and a vulnerable Fusion Builder active on the same site at the same time [7], and the six steps have to run in a fixed order to end in PHP execution [3]. Break one link and the sequence dies [13]. Most WordPress shops treat theme updates and plugin updates as separate approvals with separate owners, so the practical instruction is to ship whichever of Avada 7.16.1 or Fusion Builder 3.16.1 clears change control first [6], then take the other one when the queue allows.

That is the only slack in the story. Argus, Wordfence's internal agentic framework, found the chain, reproduced it, and produced working proof-of-concept code in about two hours [9]. Reproduction landed on 30 July, the vendor received full details on 5 August, and ThemeFusion acknowledged the report on 10 August [10]. That is eleven days between a working exploit existing and the vendor confirming it exists [12]. Discovery now runs on an agent's clock. Vendor intake and release still run on a human one.

Wordfence is withholding complete technical detail and has published only a six-step outline of the chain [8]. That buys administrators time against anyone reading the writeup for hints, and it also leaves operators with no request pattern to hunt for. Version inventory is the whole of your self-assessment. If both components were reachable at vulnerable versions before the fixes shipped, the post-exploitation list Wordfence describes includes rogue administrator accounts and database access [4], and an update does not undo either.

The million-plus figure attached to Avada is a sales count, and Wordfence's own read is that the two-component requirement significantly narrows the pool of exploitable targets [11]. No figure has been published for the size of that overlap [14], so the vendor, the researcher and the operator are all reasoning from the same gap. For anyone who runs the pair, the population statistic does not apply anyway: you are either in the intersection or you are not, and checking takes minutes.

What to watch

  • Whether Wordfence publishes the full technical detail, and how quickly exploitation attempts follow once it does.
  • Any figure from Wordfence or ThemeFusion on how many live sites run both a vulnerable Avada and a vulnerable Fusion Builder.
  • Whether Argus produces further WordPress chains at the same cadence, and how vendor intake queues cope if it does.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption28
Hype gap+18
Incentives66
Confidence54
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A critical vulnerability chain in the Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server, according to a Tuesday report by Defiant's Wordfence team.

    ReportedSupportedSource: Wordfence (Defiant)View cited source
  2. [2]

    The exploit chains six security issues into a zero-click attack; the flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score.

    ReportedSupportedView cited source
  3. [3]

    The attack comprises exploits for authorization, input-validation, trust-boundary and file-handling weaknesses, which must be executed in a specific order to enable arbitrary PHP code execution on a target server.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · August 26, 2026

    Critical Avada WordPress theme flaw enables zero-click RCE

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories