Impact
The Flatsome Theme for WordPress permits stored cross‑site scripting through its shortcodes. Unsanitized attributes let users with contributor‑level or higher privileges inject arbitrary JavaScript, which then executes for anyone who views the affected page. This flaw, an instance of OWASP CWE‑79, can lead to credential disclosure, session hijacking, or other malicious actions performed in the context of legitimate users.
Affected Systems
Vendors: UX Themes. Product: Flatsome Theme for WordPress. All releases up to and including version 3.20.0 are vulnerable; any site running these versions without an upgrade is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, but exploitation requires an already authenticated contributor or higher. The EPSS score is below 1%, confirming a low probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would have to first gain contributor access—often via social engineering or credential compromise—before using the shortcode to deliver malicious scripts.
OpenCVE Enrichment
EUVD