Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18431— Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write

Quick assessment

Affected
themefusion Avada (Fusion) Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Avada 主题在所有版本(包括 7.16 及以下版本)中,当安装了 Fusion Builder 插件且其版本为 3.16 及以下并处于激活状态时,存在任意文件写入漏洞。该漏洞源于这两个组件中授权控制和输入验证机制存在一系列缺陷,使得未经身份验证的攻击者能够将受其控制的文件写入服务器。通过利用此漏洞,攻击者可创建并执行任意 PHP 文件,从而导致远程代码执行和网站被完全控制。成功利用该漏洞需要同时满足以下条件:Avada 主题和 Fusion Builder 插件均已安装并激活,并且系统中

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18431

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
Source: CVE Program / CVE List V5
Vulnerability Description
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themefusion Avada (Fusion) Builder 0 ~ 3.16 -
ThemeFusion Avada | Website Builder For WordPress & WooCommerce 0 ~ 7.16 -

II. Public POCs for CVE-2026-18431

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18431

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18431 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18431

No comments yet


Leave a comment