Junglewise Threat Intelligence

CVE-2026-66672: Flatastic PHP Object Injection

CVE-2026-66672 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

Flatastic is a WordPress theme used to create and manage website layouts and content presentation. An unauthenticated attacker can exploit a PHP object injection vulnerability to execute arbitrary code on the web server, potentially compromising customer data, website availability, and the overall security of sites using this theme.

Technical details

The vulnerability is a PHP Object Injection flaw (CWE-502) in Flatastic theme versions 2.0 and earlier that allows unauthenticated attackers to manipulate object serialization/deserialization processing. The attack requires no authentication and is accessible over the network. Successful exploitation enables remote code execution (RCE) on the affected web server. As of the publication date, no official patch was available; Patchstack issued a mitigation rule to block known attack patterns.

Affected products

  • Flatastic Flatastic <= 2.0

Timeline

  • 2026-08-20: disclosed: Vulnerability published on Patchstack
  • 2026-02-09: other: Initially reported by João Pedro S Alcântara (Kinorth)

References

Related threats