Impact
The Flatsome WordPress theme contains an Improper Neutralization of Input During Web Page Generation flaw (CWE‑79) that causes user‑supplied data to be reflected back to the browser without proper sanitization. An attacker can craft a payload containing malicious script in a URL query parameter or form input; when the theme processes and outputs that data, the script executes in the victim’s browser, potentially stealing credentials or defacing the site. This constitutes a typical client‑side injection risk that can compromise confidentiality and integrity for end users.
Affected Systems
WordPress sites that have the UX‑themes Flatsome theme installed at version 3.20.5 or earlier are affected. Versions newer than 3.20.5 have the vulnerability fixed.
Risk and Exploitability
The CVSS score of 7.1 indicates aSS score is below 1%, meaning that, as of the latest data, the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Attackers would normally exploit this by embedding a malicious link or form field, and a victim viewing that link or submitting the form triggers the reflected XSS. No elevated privileges or back‑end access are required; the flaw relies on user interaction with the site.
OpenCVE Enrichment