Home / Aug 28, 2026 / Story
0
#9 BleepingComputer general August 26, 2026 at 21:33 UTC

Critical Avada WordPress theme flaw enables zero-click RCE

By Bill Toulas

AI Summary

A critical unauthenticated vulnerability chain in the Avada WordPress theme — one of the most widely installed commercial themes with millions of deployments — enables remote PHP code execution with zero user interaction required. An unauthenticated attacker can chain the flaws to achieve full server compromise, making this a severe risk for any site running the vulnerable Avada version. WordPress administrators should apply the patch immediately and audit for signs of prior exploitation.

Relevance score: 77.0/100

# More from August 28