Impact
An unauthenticated Cross Site Scripting vulnerability exists in WordPress Flatastic theme versions 2.0 and earlier, allowing an attacker to inject arbitrary JavaScript into pages served by sites using the vulnerable theme. When the injected script runs in a victim’s browser, it can read or modify cookies, steal session data, redirect the user, or deface the site content. The flaw permits unauthorized exploitation without authentication, thereby providing a direct attack vector for attackers to compromise user information or manipulate the front‑end experience.
Affected Systems
The vulnerability affects the Monkeysan Flatastic WordPress theme, specifically all releases with a version number of 2.0 or lower.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact and moderate to high exploitability. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog, suggesting current exploitation activity is not publicly documented. Nonetheless, because the flaw is unauthenticated and can be triggered by any user interacting with the theme, the attack vector is likely a crafted URL or form input that delivers malicious payloads to a visitor’s browser.
OpenCVE Enrichment