Avada WordPress theme flaw allows unauthenticated remote code execution
Wordfence researchers found a critical vulnerability chain, tracked as CVE-2026-18431 with a 9.8 severity score, in the Avada theme and its companion Fusion Builder plugin for WordPress. By chaining six separate weaknesses in a specific sequence, an attacker with no login credentials could execute arbitrary PHP code on a vulnerable server, fully compromising the site.