Broken Access Control in Flatsome Theme by UX Themes
CVE-2026-57731

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 July 2026

What is CVE-2026-57731?

The Flatsome Theme, developed by UX Themes, is susceptible to a broken access control vulnerability in versions up to 3.20.5. This issue allows unauthorized users to bypass restrictions, potentially leading to unauthorized access or manipulation of sensitive data. Website owners using these affected versions are recommended to apply the necessary security patches to mitigate the risk.

Affected Version(s)

Flatsome <= 3.20.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.