Impact
The Flatsome theme for WordPress suffers a broken access control flaw that permits users assigned the subscriber role to execute operations that should be limited to higher‑privileged roles. This weakness, classified as CWE‑862, can thereby allow a subscriber to elevate their privileges within the site. Based on the description, it is inferred that the attack could result in unauthorized access to restricted theme functionality, potentially exposing sensitive content or administrative capabilities.
Affected Systems
The vulnerability affects the Flatsome theme from UX‑themes, specifically all releases version 3.20.5 and older. Sites running any of these versions should upgrade to 3.20.6 or later to mitigate the flaw.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range. The EPSS score is less than 1 %, implying a low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. Attackers would need to authenticate as a WordPress user with a subscriber role on a site that hosts the affected Flatsome theme. Based on the description, it is inferred that the principal attack vector is an authenticated user exploiting the broken access control to elevate privileges.
OpenCVE Enrichment