CVE-2026-18431
Received Received - Intake

Arbitrary File Write in Avada Theme with Fusion Builder

Vulnerability report for CVE-2026-18431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: Wordfence

Description

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
themefusion avada to 7.16 (inc)
themefusion fusion_builder to 3.16 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Write flaw in the Avada WordPress theme (up to 7.16) when combined with the Fusion Builder plugin (up to 3.16). It stems from authorization and input validation weaknesses that allow unauthenticated attackers to write malicious files to the server. These files can be PHP scripts, enabling remote code execution and full site takeover.

Detection Guidance

Check if both Avada theme (version <=7.16) and Fusion Builder plugin (version <=3.16) are installed and active. Inspect server files for unexpected PHP files or modifications in directories where Avada stores content.

Impact Analysis

If exploited, attackers could create and execute arbitrary PHP files on your server, leading to complete site compromise. This includes stealing sensitive data, defacing your website, installing malware, or using your server for further attacks. The attack requires both Avada and Fusion Builder to be installed and active.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR (data protection) and HIPAA (health information privacy). Organizations may face legal penalties, reputational damage, and loss of customer trust if exploited.

Mitigation Strategies

Update Avada theme to the latest version beyond 7.16 and Fusion Builder plugin to version beyond 3.16. If updates are unavailable, disable Fusion Builder plugin and remove unauthorized PHP files from the server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart