Executive brief
Flatastic is a WordPress theme used to customize website appearance and functionality. The theme contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into websites. If exploited, attackers can steal visitor data, hijack user accounts, or deface site content without requiring any authentication.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in Flatastic theme version 2.0 and earlier that does not properly sanitize user-supplied input. The vulnerability is unauthenticated, meaning no login is required to exploit it. However, successful exploitation requires user interaction—such as a visitor clicking a malicious link or being redirected to a crafted page containing the XSS payload. An attacker can inject arbitrary JavaScript code that executes in the context of a user's browser session, potentially stealing session cookies, capturing credentials, or performing actions on behalf of the victim. No official patch is currently available; Patchstack has released a mitigation rule to block exploitation attempts.
Affected products
- Flatastic Flatastic 2.0 and earlier
Timeline
- 2026-08-20: disclosed
- 2026-02-09: other: Reported by João Pedro S Alcântara (Kinorth)