Broken Access Control in Flatsome Theme by UX Themes
CVE-2026-57730

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 July 2026

What is CVE-2026-57730?

The Flatsome theme versions up to 3.20.5 are susceptible to a broken access control vulnerability. This flaw allows unauthorized users to potentially access restricted areas and functionalities within the theme, compromising the security of the site. Site administrators are advised to take immediate action by updating to the latest version to protect their websites from potential exploits.

Affected Version(s)

Flatsome <= 3.20.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.