Impact
The Flatsome theme for WordPress contains a broken access control flaw that permits users with the contributor role to perform actions beyond their intended privileges. The flaw originates from insufficient authorization checks within the theme. Based on the description, it is inferred that a contributor could potentially modify or delete site content, thereby compromising the integrity of the site. The flaw is identified as CWE-862.
Affected Systems
All installations of the Flatsome theme version 3.20.5 or earlier on WordPress are affected. Sites running) are not vulnerable. The core WordPress platform is not impacted.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the medium severity range, and the EPSS score of < 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an authenticated contributor user must exist for exploitation; once logged in, the attacker can abuse the theme’s content management features with a straightforward attack path.
OpenCVE Enrichment