ConicPlex

Start Your Project

A laptop and a stack of file folders on a dim desk, symbolizing a file landing where it should not on a WordPress site.

On this Page

Avada, WordPress’s Best-Selling Theme, Patches a Critical Unauthenticated RCE Flaw (CVE-2026-18431)

A critical file-write bug in the Avada WordPress theme and Fusion Builder lets unauthenticated attackers achieve remote code execution. Here is what is affected and how to patch it.

Aftab Memon

September 1, 2026

ThemeFusion patched a critical remote code execution vulnerability in Avada, the WordPress theme that has sold more than a million licenses on ThemeForest, on August 26. Tracked as CVE-2026-18431, the flaw carries a CVSS score of 9.8 and lets an unauthenticated attacker write PHP files to the server by chaining weaknesses across Avada (versions up to 7.16) and its required companion plugin, Fusion Builder (versions up to 3.16). Fusion Builder ships with every Avada install, so any site running an unpatched copy of the theme carried the exposure. If you use Avada, update to version 7.16.1 and Fusion Builder to 3.16.1 now, both together.

How the Avada File-Write Bug Works

According to Wordfence’s advisory, researcher Alex Thomas found the bug through the company’s internal Argus framework on July 30 and reported it to ThemeFusion on August 5. The vendor acknowledged the report on August 10 and shipped a fix sixteen days later. The chain routes public input into a function meant to stay restricted to logged-in administrators, invokes that function outside the context those restrictions assume, and then slips past the file-handling checks that are supposed to stop arbitrary files from landing on disk. Once a file lands, an attacker can execute it directly, which opens the door to malware installation, database access, or a rogue admin account.

One caveat worth being precise about: NVD’s own description notes that exploitation requires “certain administrator-authored content to be present” alongside both components being active. That’s a real precondition, not a footnote to skip past, and it means the bug isn’t quite the guaranteed hit some early coverage implied. It’s still trivial enough to reach, and the install base large enough, that treating this as urgent is the right call regardless.

What to Do If You Run Avada

  • Update both Avada and Fusion Builder together. Patching one without the other leaves the chain intact.
  • Check the WordPress admin user list for accounts you don’t recognize, especially any created in the past month.
  • Look through your uploads directory and theme folders for PHP files that shouldn’t be there.
  • If you can’t update right away, a web application firewall rule from your host or security plugin is a stopgap, not a substitute for the patch.

This is at least the fourth critical WordPress plugin or theme disclosure in the past two weeks, following bugs in TranslatePress, WPMU DEV Dashboard, and GiveWP. None of these share a root cause. What they share is that most of the affected sites were running themes and plugins nobody had checked in months. A scheduled WordPress maintenance and audit pass, or custom-built functionality through plugin development that doesn’t carry a page builder’s entire attack surface, is usually the difference between hearing about a bug like this from a post like this one and hearing about it from an intrusion alert.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Flat illustration of a shopping cart with a purple arrow arcing over it to a checkmark, representing a WooCommerce buy now button that skips the cart page

Best WooCommerce Buy Now Button Plugins: 4 Real Options Compared

Compare 4 real WooCommerce buy now button plugins that skip the cart page, with real prices, requirements, and setup steps…

Sajil Memon

September 22, 2026

News & Updates

A laptop displaying a blurred data table interface next to a blue access badge with a padlock icon, symbolizing a broken authorization check in a WordPress table plugin

WP Table Builder Patches a High-Severity Authorization Bug (CVE-2026-6922)

WP Table Builder patched CVE-2026-6922, a high-severity flaw that let subscriber-level users trash or restore any post on a WordPress…

Aftab Memon

September 22, 2026

Platforms

Two smartphones on a desk, one showing a native app home screen and the other tapping a payment reader, with a laptop code editor blurred in the background

Native App vs. Progressive Web App: Which One Actually Fits Your Business in 2026?

A practical framework for deciding between a native app and a progressive web app in 2026, with real costs, hardware…

Husen Memon

September 21, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant