Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Flatsome WordPress theme contains an Improper Neutralization of Input During Web Page Generation flaw (CWE‑79) that causes user‑supplied data to be reflected back to the browser without proper sanitization. An attacker can craft a payload containing malicious script in a URL query parameter or form input; when the theme processes and outputs that data, the script executes in the victim’s browser, potentially stealing credentials or defacing the site. This constitutes a typical client‑side injection risk that can compromise confidentiality and integrity for end users.

Affected Systems

WordPress sites that have the UX‑themes Flatsome theme installed at version 3.20.5 or earlier are affected. Versions newer than 3.20.5 have the vulnerability fixed.

Risk and Exploitability

The CVSS score of 7.1 indicates aSS score is below 1%, meaning that, as of the latest data, the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Attackers would normally exploit this by embedding a malicious link or form field, and a victim viewing that link or submitting the form triggers the reflected XSS. No elevated privileges or back‑end access are required; the flaw relies on user interaction with the site.

Generated by OpenCVE AI on August 1, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Flatsome theme to the latest version (>=3.20.6).
  • If the theme cannot be updated, disable or uninstall it to eliminate the vulnerability.
  • Implement a Web Application Firewall rule or Content Security Policy to block or sanitize untrusted script content.

Generated by OpenCVE AI on August 1, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.
Title WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.476Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57728

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:04.933Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')