Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Is Trump admin importing contaminated beef from Argentina? Unpacking the claim

    August 27, 2026

    Australia news live: tour operator has grave fears for group of 15 Australians aged 11 to 63 missing amid Nepal flooding | Australia news

    August 27, 2026

    ‘We weren’t going to be lectured’: Howard revisits Tampa, 25 years on

    August 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Is Trump admin importing contaminated beef from Argentina? Unpacking the claim
    • Australia news live: tour operator has grave fears for group of 15 Australians aged 11 to 63 missing amid Nepal flooding | Australia news
    • ‘We weren’t going to be lectured’: Howard revisits Tampa, 25 years on
    • Viral AI startup Instinct has raised $350 million at a $2.5 billion valuation
    • Critical Avada WordPress theme flaw enables zero-click RCE
    • SEC Advances Crypto Custody Rules for Investment Advisers
    • What you eat before age 2 may affect your health 70 years later
    • Brazil relaxes Belo Monte water rule amid El Niño-fueled Amazon drought risk
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Avada WordPress theme flaw enables zero-click RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 27, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.

    The exploit chains six security issues into a zero-click attack. The flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score.

    The attack comprises exploits for authorization, input-validation, trust-boundary, and file-handling weaknesses, which must be executed in a specific order to enable arbitrary PHP code execution on a target server.

    image

    Hackers who successfully exploit these vulnerabilities could fully compromise websites for malicious activities ranging from planting malware and accessing databases to redirecting visitors to malicious sites or adding rogue admin accounts.

    CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16, researchers at Defiant’s Wordfence team say in a report on Tuesday.

    While ThemeFusion, the developer behind Avada and Fusion Builder, fixed the vulnerability, Wordfence is not sharing complete technical details to give administrators sufficient time to install the latest updates and has only provided the following attack chain overview:

    1. Exposing attacker-controlled input through a public request
    2. Passing that input to functionality restricted from anonymous users
    3. Invoking a privileged component outside its intended context
    4. Using request data to influence trusted state
    5. Accessing an insufficiently protected administrative operation
    6. Bypassing file-handling restrictions on what could be written and where

    Despite the critical severity of the flaw, the researchers clarify that exploitation requires a vulnerable version of both the Avada theme and the Fusion Builder plugin to be active on the target website.

    Although the Avada theme is popular, with more than 1 million sales, the prerequisites for exploiting CVE-2026-18431 significantly narrow the pool of potential targets.

    Wordfence discovered the six-step vulnerability chain using an internal agentic framework called Argus, which also developed proof-of-concept exploit code, all in about two hours.

    Argus found and successfully reproduced the flaw on July 30, and the researchers shared the full details to the vendor on August 5. ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Avada critical enables Flaw RCE theme WordPress zeroclick
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

    Chrome 152 Patches Over 300 Vulnerabilities

    Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

    AI Speeds Up Malware Development, Not Its Success Rate: Analysis

    Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Is Trump admin importing contaminated beef from Argentina? Unpacking the claim

    August 27, 2026

    Australia news live: tour operator has grave fears for group of 15 Australians aged 11 to 63 missing amid Nepal flooding | Australia news

    August 27, 2026

    ‘We weren’t going to be lectured’: Howard revisits Tampa, 25 years on

    August 27, 2026

    Viral AI startup Instinct has raised $350 million at a $2.5 billion valuation

    August 27, 2026
    Latest Posts

    Andy Burnham wants to fix social care. It’s personal for him and for a lot of us too | John Crace

    July 29, 2026

    France orders Russian journalist Xenia Fedorova to leave country over alleged Kremlin propaganda

    July 29, 2026

    Russia-Ukraine War: The Wildberries Theory of Moscow’s Defeat

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Is Trump admin importing contaminated beef from Argentina? Unpacking the claim

    August 27, 2026

    Australia news live: tour operator has grave fears for group of 15 Australians aged 11 to 63 missing amid Nepal flooding | Australia news

    August 27, 2026

    ‘We weren’t going to be lectured’: Howard revisits Tampa, 25 years on

    August 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.