Mark RadarMARK RADAR
About
EN
Sign in

Avada Patches Critical RCE as AI Agent Builds Six-Step Exploit Chain

1 reports · First detected 2026-08-27 · Last active 2026-08-27

Avada, a widely used commercial theme in the WordPress ecosystem, has patched CVE-2026-18431, a remote code execution vulnerability carrying a critical CVSS score of 9.8. Successful exploitation could allow an attacker to run commands on an affected server, alter content or take control of a website, underscoring the broad supply-chain exposure created by software shared across many WordPress installations.

Argus, an AI research agent developed by Wordfence, identified and validated the vulnerability by autonomously linking six weaknesses into a working attack path. The agent completed the chain in two hours without human intervention, demonstrating how AI systems can accelerate complex security research. Avada’s developers released an updated version in 2026 and urged administrators to upgrade promptly because addressing individual flaws may not block the full exploit chain.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)