Affected Systems

Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously. Over 1 million Avada licenses sold, but actual vulnerable population is subset with both theme and plugin enabled.

Exploitation Status

No active exploitation reported. Wordfence withheld full technical details to allow patching time. Proof-of-concept exists (developed by Wordfence Argus framework) but not publicly released. Vulnerability disclosed responsibly; patches available as of August 25, 2026.

Business Impact

Unauthenticated remote code execution enables full site compromise: arbitrary PHP execution, database access, malware injection, admin account creation, and traffic redirection. Attack chains six flaws (authorization bypass, input validation, trust boundary, file handling) in specific sequence for zero-click exploitation. CVSS 9.8 critical. Risk limited to sites running both vulnerable Avada theme AND Fusion Builder plugin concurrently.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update Avada theme to version 7.16.1 or later immediately on all WordPress installations
  • Update Fusion Builder plugin to version 3.16.1 or later on all sites where installed
  • Audit WordPress sites for unauthorized admin accounts, unexpected PHP files in wp-content/uploads and theme directories, and database modifications
  • Review web server and WordPress logs from July 30 onward for suspicious unauthenticated POST requests to Avada/Fusion Builder endpoints
  • If immediate patching is not possible, temporarily disable the Fusion Builder plugin until updates can be applied