THREAT OPS › Threat News › Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE
Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE
<h1>Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE</h1> <p>A critical vulnerability chain tracked as <strong>CVE-2026-18431</strong> affects the <strong>Avada WordPress theme</strong> and its required <strong>Fusion Builder plugin, now branded as Avada Builder</strong>. The flaw carries a CVSS score of <strong>9.8</strong> and can allow an unauthenticated attacker to write and execute
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-18431cve
- https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/url
Original source: https://socradar.io/blog/cve-2026-18431-avada-wordpress-rce/