Cross-site Scripting Vulnerability in UX-themes Flatsome Theme
CVE-2026-57728
7.1HIGH
What is CVE-2026-57728?
The Flatsome theme by UX-themes contains a vulnerability that allows for Reflected Cross-site Scripting (XSS). This flaw enables attackers to inject malicious scripts into web pages returned to users, potentially compromising user information and security. The affected versions range from n/a to 3.20.5, making it crucial for users to update their theme to prevent exploitation.
Affected Version(s)
Flatsome 0 <= 3.20.5