Skip to content
Breaking
Hong Kong netball star chases bigger goal, on court and in courtMoody’s Analytics slashes Philippine growth forecast to 3%Colombia mulls locking up dangerous criminals on prison shipsCritical Avada WordPress flaw enables zero-click server takeoverGPUThor attack bypasses NVIDIA ECC protection to enable root accessUS imposes 50% tariffs on US$20 billion of Canadian goods after trade talks failNimbus Manticore adds SSH tunneler and TWOSTROKE-like backdoor to toolsetSingapore awards 200 MW of data-centre capacity to four operators on Aug 21Bursa Malaysia ends higher as YTL, banking stocks lift marketAnthropic secures $45 billion AI compute deal with NscaleSime Darby Property's recurring‑income push gains tractionChina bet big on AI diffusion with domestic chipmaking breakthroughGemini Live splits AI features into Spark and Daily Brief, cluttering the interfaceClean water supply strengthened for drought-hit Central Java residentsPacific Islands Forum opens with climate fund and China’s sway in focusWhen AI infrastructure becomes the target: Securing gateways and control pointsThe inside story on why OpenAI agents hacked Hugging FaceThe Download: Kids issue arrives, Bill Gates reveals his AI fearsInaugural IEEE student research conference backed by RM3.75 million grantA New NASA Design Turbocharges Nuclear SpacecraftHong Kong netball star chases bigger goal, on court and in courtMoody’s Analytics slashes Philippine growth forecast to 3%Colombia mulls locking up dangerous criminals on prison shipsCritical Avada WordPress flaw enables zero-click server takeoverGPUThor attack bypasses NVIDIA ECC protection to enable root accessUS imposes 50% tariffs on US$20 billion of Canadian goods after trade talks failNimbus Manticore adds SSH tunneler and TWOSTROKE-like backdoor to toolsetSingapore awards 200 MW of data-centre capacity to four operators on Aug 21Bursa Malaysia ends higher as YTL, banking stocks lift marketAnthropic secures $45 billion AI compute deal with NscaleSime Darby Property's recurring‑income push gains tractionChina bet big on AI diffusion with domestic chipmaking breakthroughGemini Live splits AI features into Spark and Daily Brief, cluttering the interfaceClean water supply strengthened for drought-hit Central Java residentsPacific Islands Forum opens with climate fund and China’s sway in focusWhen AI infrastructure becomes the target: Securing gateways and control pointsThe inside story on why OpenAI agents hacked Hugging FaceThe Download: Kids issue arrives, Bill Gates reveals his AI fearsInaugural IEEE student research conference backed by RM3.75 million grantA New NASA Design Turbocharges Nuclear Spacecraft
AI Edge

Critical Avada WordPress flaw enables zero-click server takeover

Wordfence researchers at Defiant disclosed CVE-2026-18431, a critical nine-point-eight severity chain that lets unauthenticated attackers execute arbitrary PHP code on any server running vulnerable Avada themes up to 7.16 or Fusion Builder plugins up to 3.16.

Source: BleepingComputer · August 26, 2026 at 11:31 PM · AI-assisted report

Single-source
Critical Avada WordPress flaw enables zero-click server takeover
Image: bleepingcomputer.com

MALAYSIA, 27 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

Critical Avada WordPress Theme Flaw Exposes Sites to Zero-Click Remote Code Execution

Market Impact

A critical vulnerability chain in the widely used Avada WordPress theme enables unauthenticated attackers to execute arbitrary PHP code on affected servers, according to a report by Defiant’s Wordfence team. The flaw, tracked as CVE-2026-18431 with a severity score of 9.8, combines six distinct security issues into a zero-click attack vector. Exploitation requires a vulnerable version of both the Avada theme (up to 7.16) and the Fusion Builder plugin (up to 3.16), limiting the pool of potential targets despite the theme’s popularity with over 1 million sales.

The attack chain exploits weaknesses in authorization, input validation, trust boundaries, and file handling, executed in a precise sequence to achieve remote code execution. Successful exploitation could allow threat actors to fully compromise websites, enabling activities such as malware deployment, database access, visitor redirection to malicious sites, or the creation of rogue administrator accounts. Researchers at Wordfence discovered the flaw using their internal agentic framework, Argus, which autonomously identified and reproduced the vulnerability in approximately two hours. The team confirmed the issue on July 30 and disclosed it to ThemeFusion on August 5. The vendor acknowledged the report on August 10 and released patched versions—Avada 7.16.1 and Fusion Builder 3.16.1—on August 25.

For the Malaysian market, where WordPress powers an estimated 40% of websites, the risk is concentrated among users running outdated versions of Avada and Fusion Builder. Small and medium enterprises, as well as digital agencies, are particularly exposed due to reliance on these tools for website development. Cybersecurity firm LE Global Services Sdn Bhd noted that while the zero-click nature of the exploit raises concerns, the dual-component dependency reduces the attack surface. “Most Malaysian WordPress users update plugins regularly, but those running legacy themes or custom builds may remain vulnerable,” said a spokesperson. Local hosting providers have begun issuing advisories, urging customers to apply the latest patches immediately.

In the broader WordPress ecosystem, CVE-2026-18431 underscores ongoing challenges in supply-chain security, particularly for premium themes with large user bases. ThemeFusion, the developer behind Avada, has historically maintained a strong market presence in Malaysia, with many local developers integrating the theme into client projects. The rapid patching timeline—just 20 days from disclosure to fix—reflects improved responsiveness in the WordPress security community. However, the incident highlights the persistent risk of chained vulnerabilities, where multiple flaws must align for exploitation to succeed.

Looking ahead, security researchers anticipate increased scrutiny of WordPress theme and plugin interdependencies. The Wordfence team has emphasized that while prevention tools can detect initial exploitation attempts, post-compromise detection remains critical. “Once attackers gain a foothold using valid credentials, traditional prevention measures become far less effective,” the report states. For Malaysian businesses, this reinforces the need for layered security, including regular audits, automated patch management, and real-time monitoring. ThemeFusion has urged users to update immediately, warning that unpatched systems remain at risk until the latest versions are installed.

Related: ThemeFusion · Malaysia

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.