A critical vulnerability chain has been discovered in the popular Avada theme for WordPress, allowing an attacker to execute arbitrary PHP code on a target server without even requiring valid login credentials. This zero-click Remote Code Execution (RCE) attack can be executed by chaining six security issues together, and its severity is rated 9.8 out of 10.
The attack affects not only the Avada theme itself but also the Fusion Builder plugin, which is used in conjunction with Avada. According to researchers at Defiant’s Wordfence team, the vulnerability chain exploits weaknesses in authorization, input-validation, trust-boundary, and file-handling, all of which must be executed in a specific order to enable RCE on a target server. This means that an attacker can potentially plant malware, access databases, redirect visitors to malicious sites, or even add rogue admin accounts.
The affected versions of Avada are up to 7.16, while the Fusion Builder plugin is also vulnerable if it’s installed in conjunction with Avada. However, there is some good news: ThemeFusion, the developer behind both plugins, has already fixed the vulnerability and released updates for Avada 7.16.1 and Fusion Builder 3.16.1.
The fact that this attack requires a specific chain of events to occur means that it’s not as straightforward as simply exploiting one or two vulnerabilities. Wordfence researchers used an internal tool called Argus, which developed proof-of-concept exploit code in just over two hours, to discover the vulnerability chain. This highlights the importance of having robust security tools and monitoring systems in place.
While the severity of this flaw is critical, it’s worth noting that exploiting it requires a vulnerable version of both Avada and Fusion Builder to be active on the target website. However, with more than 1 million sales, Avada is one of the most popular themes for WordPress, making it a significant concern for administrators.
In practical terms, this means that if you’re using Avada or Fusion Builder on your WordPress site, it’s essential to update both plugins to the latest versions as soon as possible. This will help prevent potential attackers from exploiting the vulnerability chain and executing RCE attacks on your server.
Source: Bleeping Computer — 2026-08-26