Wordfence says the Avada WordPress theme and Fusion Builder plugin from ThemeFusion have a critical zero-click remote code execution chain, tracked as CVE-2026-18431, affecting Avada up to 7.16 and Fusion Builder up to 3.16. ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 after Wordfence reported the issue.
The attack works by feeding attacker-controlled input through six checks and trust failures until WordPress treats it like an authorized admin action. Because the chain needs both vulnerable components in place, a site with only one side updated can still end up at arbitrary PHP execution, with follow-on access to databases, malware placement, rogue admin creation, or redirects.
That makes version mix-ups the enduring risk: if Avada and Fusion Builder are patched on different cadences, the site can stay exposed even after some remediation. The reporting does not show active exploitation, but the prerequisite list is specific enough that partial cleanup may leave the dangerous path intact.