If your site runs the Avada theme, update it today. A critical flaw lets an attacker take over your site without ever logging in.
What happened
Avada, a WordPress theme sold on ThemeForest with over a million copies sold, has an unauthenticated remote code execution vulnerability in the Fusion Patcher, the component that handles file-based updates for the theme. ThemeFusion, the company behind Avada, says the flaw lets an attacker with no account write malicious PHP files to the server and run them, leading to full site compromise.
Wordfence rated the flaw critical at 9.8 out of 10. It isn’t one simple bug. Wordfence says an attacker has to chain six separate weaknesses in a specific order, starting with attacker input reaching internal code not meant for anonymous users, and ending with the Fusion Patcher writing attacker-controlled content to disk without proper authorization checks. Wordfence found the chain using Argus, a new AI research agent the company built for deep, multi-step exploit hunting, which reproduced the full six-step attack from scratch in about two hours with no human help.
Exploiting the flaw also requires certain administrator-authored content to already be present on the site, though Wordfence hasn’t specified what kind.
Who is affected
Every site running Avada up to and including version 7.16, with the bundled Fusion Builder plugin up to and including version 3.16, is vulnerable. Wordfence reported the flaw to ThemeFusion on August 10, and ThemeFusion had a pre-release patch ready two days later.
What to do
Update both the Avada theme and Fusion Builder to their latest versions right away. ThemeFusion fixed the flaw in Avada 7.16.1 and Fusion Builder 3.16.1.
End of article