Description
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Flatsome WordPress theme copies a missing authorization flaw that lets an attacker bypass intended access controls and reach or modify content that should be protected. Because the check for user authentication or role is omitted, an unauthenticated or low‑privileged user can execute privileged actions on the site. This integrity and confidentiality compromise can result in the disclosure of sensitive information or the tampering of posts, pages, or custom theme data. The flaw corresponds to CWE-862, missing authorization.

Affected Systems

The vulnerability impacts the UX‑themes Flatsome theme version 3.20.5 and earlier. No lower bound is specified in the advisory, so any WordPress installation that has any Flatsome version in that range could be affected. Sites that have not upgraded beyond 3.20.5 are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface, where an attacker can send crafted HTTP requests to theme‑related URLs and exploit the broken access control to perform actions normally protected by authentication.

Generated by OpenCVE AI on August 1, 2026 at 10:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Flatsome theme to the latest release (3.20.6 or later) which contains the authorization fix
  • Apply role‑based access controls or custom middleware on theme‑related endpoints to enforce proper authentication and authorization
  • Configure the web server or security plugin to log or block suspicious requests to theme URLs and monitor for unauthorized access attempts

Generated by OpenCVE AI on August 1, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
Title WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.341Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57729

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:03.527Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses