<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ThemeFusion - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/themefusion/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 16:20:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/themefusion/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Write in Avada Theme and Fusion Builder</title><link>https://feed.craftedsignal.io/briefs/2026-08-avada-rce/</link><pubDate>Wed, 26 Aug 2026 16:20:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-avada-rce/</guid><description>An unauthenticated arbitrary file write vulnerability in the Avada WordPress theme and Fusion Builder plugin allows remote attackers to execute arbitrary PHP code and compromise the host.</description><content:encoded><![CDATA[<p>ThemeFusion's Avada theme for WordPress and the associated Fusion Builder plugin contain critical authorization and input validation vulnerabilities, tracked as CVE-2026-18431. These flaws affect Avada versions up to 7.16 and Fusion Builder versions up to 3.16. The vulnerability enables unauthenticated attackers to write arbitrary files to the server's file system by chaining specific weaknesses within the two components. Successful exploitation requires both components to be active and the presence of specific administrator-authored content. By crafting malicious requests, an attacker can upload arbitrary PHP files and achieve remote code execution (RCE), leading to a complete compromise of the WordPress site. Defenders must prioritize upgrading to patched versions to mitigate this critical RCE risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full site compromise, allowing attackers to execute arbitrary code, modify site content, and access sensitive database information. Given the popularity of the Avada theme, the potential victim count is significant across various sectors including e-commerce, corporate blogs, and professional services that utilize WordPress for web presence.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Avada theme and Fusion Builder plugin to the latest versions immediately to address CVE-2026-18431.</li>
<li>Audit the WordPress uploads directory and active theme directories for unexpected PHP files or recent modifications to existing template files.</li>
<li>Implement web application firewall (WAF) rules to inspect and block suspicious POST requests directed at themes or plugins containing filename parameters or unexpected extensions.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>