type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, wordpress, avada, theme, arbitrary-file-write, rce, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false
CVE-2026-18431
CVE-2026-18431 is a critical vulnerability (CVSS 9.8) in the Avada WordPress theme, one of the most widely deployed premium themes on the platform. The flaw is an arbitrary file write that enables remote code execution when the Fusion Builder component is active, giving an attacker full control of an affected website.
The flaw was disclosed by Wordfence and Patchstack as part of a batch of five critical WordPress plugin and theme vulnerabilities published on 29 August 2026. No in-the-wild exploitation had been disclosed at publication, but the theme's wide deployment makes the exposure significant for site owners and for Australian agencies managing large WordPress estates.