Summary
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
Take Action:
If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)