Description
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
Published: 2026-07-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Flatsome theme for WordPress suffers a broken access control flaw that permits users assigned the subscriber role to execute operations that should be limited to higher‑privileged roles. This weakness, classified as CWE‑862, can thereby allow a subscriber to elevate their privileges within the site. Based on the description, it is inferred that the attack could result in unauthorized access to restricted theme functionality, potentially exposing sensitive content or administrative capabilities.

Affected Systems

The vulnerability affects the Flatsome theme from UX‑themes, specifically all releases version 3.20.5 and older. Sites running any of these versions should upgrade to 3.20.6 or later to mitigate the flaw.

Risk and Exploitability

The CVSS score of 4.3 places the vulnerability in the moderate range. The EPSS score is less than 1 %, implying a low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. Attackers would need to authenticate as a WordPress user with a subscriber role on a site that hosts the affected Flatsome theme. Based on the description, it is inferred that the principal attack vector is an authenticated user exploiting the broken access control to elevate privileges.

Generated by OpenCVE AI on July 21, 2026 at 11:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Flatsome theme to a version newer than 3.20.5 to remove the vulnerability.
  • If an immediate upgrade is not possible, restrict subscriber capabilities so they cannot access the affected functionality, using a role editor plugin or custom access checks, addressing the CWE‑862 vulnerability.
  • Review and tighten the theme’s internal access control rules to ensure that only authorized roles can perform privileged actions, following the principle of least privilege.

Generated by OpenCVE AI on July 21, 2026 at 11:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
Title WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:41:30.001Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57730

cve-icon Vulnrichment

Updated: 2026-07-02T12:41:26.753Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:45:03Z

Weaknesses