Executive brief
Flatsome is a popular WordPress theme used for building e-commerce websites. A security flaw in the theme's access control settings allows unauthorized individuals to bypass security checks. This could lead to the exposure of sensitive information or unauthorized access to site features, potentially impacting customer data and business operations.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the UX-themes Flatsome theme through version 3.20.5. The flaw stems from insufficient validation of authorization levels or missing nonce tokens in certain functions. An unauthenticated remote attacker can exploit this to perform actions or access data that should be restricted to higher-privileged users. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.
Affected products
- UX-themes Flatsome <= 3.20.5
Timeline
- 2026-02-16: other: Vulnerability reported by researcher Bonds
- 2026-07-06: advisory: Initial disclosure by Patchstack
- 2026-07-13: disclosed: CVE published to NVD dataset