News Security Avada zero-click RCE chain (CVE-2026-18431) and a separate Fusion Builder XSS: what WordPress admins should know August 31, 2026 by Alex Mira | Leave a Comment A critical six-step chain in the Avada theme enables zero-click RCE (CVE-2026-18431), and a separate stored XSS impacts Fusion Builder up to 3.15.6 (CVE-2026-16654). Here’s what’s confirmed and what to update now. Read more » Avada theme CVE-2026-16654 CVE-2026-18431 Fusion Builder Remote code execution Stored XSS WordPress security