CVE-2026-18431_Avada Theme and Fusion Builder Plugin Remote Code Execution Vulnerability

Release Date: 26th August 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate WordPress websites using the Avada theme together with the Fusion Builder plugin. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-18431 is a critical remote code execution vulnerability affecting sites that run both the Avada theme and the Fusion Builder plugin together. It is a broken access control flaw (CWE-862): missing authorization checks let an unauthenticated attacker write attacker-controlled files to the server.

An attacker can use this arbitrary file write to create and execute PHP files of their choosing, resulting in full remote code execution on the web server.

Reference

  1. https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/
  2. https://www.cve.org/CVERecord?id=CVE-2026-18431