Avada 7.16.1 patches an RCE, and two plugins leaked reset links
Avada 7.16.1 fixes an unauthenticated remote code execution chain that needed Fusion Builder active too. TranslatePress 3.3.2 and InfusedWoo Pro 5.1.18 both close holes that handed an administrator password reset link to an attacker.