THREATOPS
THREAT OPSThreat News › Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE

Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE

medsocradar_blogPublished 2026-08-27

<h1>Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE</h1> <p>A critical vulnerability chain tracked as <strong>CVE-2026-18431</strong> affects the <strong>Avada WordPress theme</strong> and its required <strong>Fusion Builder plugin, now branded as Avada Builder</strong>. The flaw carries a CVSS score of <strong>9.8</strong> and can allow an unauthenticated attacker to write and execute

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/cve-2026-18431-avada-wordpress-rce/