Critical Avada WordPress Flaw Enables Zero-Click Remote Code Execution
A critical vulnerability chain (CVE-2026-18431) in the popular Avada WordPress theme and Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code on affected websites without user interaction. The flaw has a CVSS score of 9.8 and combines six separate security weaknesses into a zero-click exploit. Successful exploitation could grant extensive control over a website, including installing malware or accessing databases. The vulnerability affects Avada versions through 7.16 and Fusion Builder versions through 3.16.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai