Executive brief
Flatsome, a popular WordPress theme used for building e-commerce websites, contains a security flaw that allows users with basic 'Subscriber' accounts to access information or perform actions they should not be authorized to see. While the impact is considered low, it could allow a registered user to bypass intended restrictions within the site's management interface. As of the latest report, no official patch has been released to address this issue.
Technical details
A broken access control vulnerability exists in the Flatsome theme for WordPress (versions <= 3.20.5) due to missing authorization (CWE-862). The flaw allows an authenticated attacker with low-level 'Subscriber' privileges to bypass access controls via network requests. According to the advisory, the vulnerability could lead to unauthorized access to certain functions or data, though the impact is limited to low-level information disclosure or minor unauthorized actions. No official patch is currently available, and the vulnerability remains unpatched in version 3.20.5.
Affected products
- UX-themes Flatsome <= 3.20.5
Timeline
- 2026-02-16: disclosed: Reported by researcher Bonds
- 2026-07-01: advisory: Published by Patchstack
- 2026-07-02: other: CVE record published by NVD