security1 distinct publisher
Six bugs, one order of operations: Avada's zero-click chain is a same-day patch
Wordfence says CVE-2026-18431 lets an unauthenticated attacker run PHP on sites running both a vulnerable Avada theme and Fusion Builder. Updating either component breaks the chain.
Publishers:bleepingcomputer.com
Reality
- Evidence52
- Adoption28
- Hype gap+18
- Incentives66