{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fusion-builder--3.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18431"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Avada (\u003c= 7.16)","Fusion Builder (\u003c= 3.16)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ThemeFusion"],"content_html":"\u003cp\u003eThemeFusion's Avada theme for WordPress and the associated Fusion Builder plugin contain critical authorization and input validation vulnerabilities, tracked as CVE-2026-18431. These flaws affect Avada versions up to 7.16 and Fusion Builder versions up to 3.16. The vulnerability enables unauthenticated attackers to write arbitrary files to the server's file system by chaining specific weaknesses within the two components. Successful exploitation requires both components to be active and the presence of specific administrator-authored content. By crafting malicious requests, an attacker can upload arbitrary PHP files and achieve remote code execution (RCE), leading to a complete compromise of the WordPress site. Defenders must prioritize upgrading to patched versions to mitigate this critical RCE risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full site compromise, allowing attackers to execute arbitrary code, modify site content, and access sensitive database information. Given the popularity of the Avada theme, the potential victim count is significant across various sectors including e-commerce, corporate blogs, and professional services that utilize WordPress for web presence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Avada theme and Fusion Builder plugin to the latest versions immediately to address CVE-2026-18431.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress uploads directory and active theme directories for unexpected PHP files or recent modifications to existing template files.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect and block suspicious POST requests directed at themes or plugins containing filename parameters or unexpected extensions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:20:25Z","date_published":"2026-08-26T16:20:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-avada-rce/","summary":"An unauthenticated arbitrary file write vulnerability in the Avada WordPress theme and Fusion Builder plugin allows remote attackers to execute arbitrary PHP code and compromise the host.","title":"Arbitrary File Write in Avada Theme and Fusion Builder","url":"https://feed.craftedsignal.io/briefs/2026-08-avada-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Fusion Builder (\u003c= 3.16)","version":"https://jsonfeed.org/version/1.1"}