Executive brief
Avada, a popular WordPress website builder theme, contains a critical vulnerability that allows unauthenticated attackers to upload arbitrary files to a website server when used with the Fusion Builder plugin. An attacker can exploit this flaw to write malicious PHP files and execute arbitrary code, leading to complete site compromise and unauthorized access to customer data.
Technical details
The vulnerability is an arbitrary file write flaw resulting from a chain of authorization and input validation weaknesses in the Avada theme (versions up to 7.16) and Fusion Builder plugin (versions up to 3.16). An unauthenticated attacker can bypass authorization checks and validation to write attacker-controlled files to the server. The attack is network-reachable and requires no user interaction or authentication, though exploitation requires both components to be installed and active, plus specific administrator-authored content to be present on the site. Successful exploitation allows remote code execution through arbitrary PHP file creation, resulting in complete site takeover.
Affected products
- Automattic Avada up to and including 7.16
- Automattic Fusion Builder up to and including 3.16
Timeline
- 2026-08-26: disclosed