Executive brief
Flatsome, a popular WordPress theme used for building e-commerce websites, contains a security flaw that allows users with low-level 'Contributor' accounts to bypass intended access restrictions. This could allow an internal user to access sensitive information or perform actions they are not authorized to do. While the risk is primarily from authenticated users, it could lead to unauthorized data exposure within the website's management interface.
Technical details
A broken access control vulnerability exists in the Flatsome theme for WordPress (versions up to and including 3.20.5) due to missing authorization checks (CWE-862). An attacker authenticated with 'Contributor' level permissions can exploit this flaw over the network without user interaction. The vulnerability allows for unauthorized access to data (Confidentiality: High), though it does not currently appear to allow for unauthorized data modification or service disruption. As of the advisory date, no official patch has been released.
Affected products
- UX-themes Flatsome <= 3.20.5
Timeline
- 2026-02-16: other: Vulnerability reported by researcher Bonds
- 2026-07-01: advisory: Patchstack published advisory
- 2026-07-02: disclosed: CVE published to NVD