SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Six bugs, one order of operations: Avada's zero-click chain is a same-day patch
Wordfence says CVE-2026-18431 lets an unauthenticated attacker run PHP on sites running both a vulnerable Avada theme and Fusion Builder. Updating either component breaks the chain.
The Watch · Security desk
What happened
- Wordfence says six chained flaws in the Avada WordPress theme allow unauthenticated arbitrary PHP execution, tracked together as CVE-2026-18431 at 9.8 severity.
- ThemeFusion shipped Avada 7.16.1 and Fusion Builder 3.16.1 the day before the advisory went out.
- Wordfence says the attack only works where vulnerable versions of both the theme and the plugin are active.
Why it matters
- decision Teams with a slow theme pipeline are not blocked: whichever of the two updates clears change control first is enough to break the sequence, which turns one urgent decision into two ordinary ones.
- exposure Nothing has to be phished or clicked, so who is reachable is decided purely by installed versions and internet exposure, and any site already hit needs cleanup that an update does not perform.
- constraint With the technical detail withheld, defenders have no request signature to search logs for, so version inventory is the only verification available to them.
- precedent A chain built in hours against a vendor confirmation measured in days sets the expectation that patch windows will be sized by automated discovery rather than by researcher backlog.
The prerequisite sitting in the middle of Wordfence's advisory is the useful part. Exploitation needs a vulnerable Avada and a vulnerable Fusion Builder active on the same site at the same time [7], and the six steps have to run in a fixed order to end in PHP execution [3]. Break one link and the sequence dies [13]. Most WordPress shops treat theme updates and plugin updates as separate approvals with separate owners, so the practical instruction is to ship whichever of Avada 7.16.1 or Fusion Builder 3.16.1 clears change control first [6], then take the other one when the queue allows.
That is the only slack in the story. Argus, Wordfence's internal agentic framework, found the chain, reproduced it, and produced working proof-of-concept code in about two hours [9]. Reproduction landed on 30 July, the vendor received full details on 5 August, and ThemeFusion acknowledged the report on 10 August [10]. That is eleven days between a working exploit existing and the vendor confirming it exists [12]. Discovery now runs on an agent's clock. Vendor intake and release still run on a human one.
Wordfence is withholding complete technical detail and has published only a six-step outline of the chain [8]. That buys administrators time against anyone reading the writeup for hints, and it also leaves operators with no request pattern to hunt for. Version inventory is the whole of your self-assessment. If both components were reachable at vulnerable versions before the fixes shipped, the post-exploitation list Wordfence describes includes rogue administrator accounts and database access [4], and an update does not undo either.
The million-plus figure attached to Avada is a sales count, and Wordfence's own read is that the two-component requirement significantly narrows the pool of exploitable targets [11]. No figure has been published for the size of that overlap [14], so the vendor, the researcher and the operator are all reasoning from the same gap. For anyone who runs the pair, the population statistic does not apply anyway: you are either in the intersection or you are not, and checking takes minutes.
What to watch
- Whether Wordfence publishes the full technical detail, and how quickly exploitation attempts follow once it does.
- Any figure from Wordfence or ThemeFusion on how many live sites run both a vulnerable Avada and a vulnerable Fusion Builder.
- Whether Argus produces further WordPress chains at the same cadence, and how vendor intake queues cope if it does.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence52
- Adoption28
- Hype gap+18
- Incentives66
- Confidence54
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A critical vulnerability chain in the Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server, according to a Tuesday report by Defiant's Wordfence team.
- [2]
The exploit chains six security issues into a zero-click attack; the flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score.
- [3]
The attack comprises exploits for authorization, input-validation, trust-boundary and file-handling weaknesses, which must be executed in a specific order to enable arbitrary PHP code execution on a target server.
- [4]
Successful exploitation could fully compromise websites, including planting malware, accessing databases, redirecting visitors to malicious sites, or adding rogue admin accounts.
- [5]
CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.
- [6]
ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 the day before Wordfence's Tuesday report.
- [7]
Wordfence clarifies that exploitation requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target website.
- [8]
Wordfence is not sharing complete technical details, in order to give administrators time to install updates, and has provided only a six-step overview of the attack chain.
- [9]
Wordfence discovered the six-step vulnerability chain using an internal agentic framework called Argus, which also developed proof-of-concept exploit code, all in about two hours.
- [10]
Argus found and successfully reproduced the flaw on July 30; researchers shared full details with the vendor on August 5; ThemeFusion acknowledged the report on August 10.
- [11]
The Avada theme has more than 1 million sales, but the prerequisites for exploiting CVE-2026-18431 significantly narrow the pool of potential targets.
- [12]
Eleven days elapsed between Argus reproducing the exploit and ThemeFusion acknowledging the report, of which six were before the vendor was notified.
- [13]
Because the six steps must run in a specific order and both a vulnerable theme and a vulnerable plugin must be active, updating either component alone removes a required link and defeats the chain.
- [14]
No figure has been published for the number of live sites running both a vulnerable Avada and a vulnerable Fusion Builder.
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comCritical Avada WordPress theme flaw enables zero-click RCE
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- WordPress Theme and Plugin SecurityFollow
- Vulnerability Chaining and Exploit OrderingFollow
- Coordinated Disclosure and EmbargoesFollow
- Unauthenticated Remote Code ExecutionFollow
- Agentic AI Vulnerability DiscoveryFollow