← WordPress Vulnerabilities
WordPress security by component

flatastic

flatastic is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.8.

Theme slug: flatastic

CVE-2026-66673: Flatastic permits unauthenticated cross-site scripting

Flatastic <= 2.0 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.

PublishedAug 20, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for flatastic
Safe version
Aug 20, 2026 CVE-2026-66673
Flatastic permits unauthenticated cross-site scripting
Flatastic <= 2.0 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
See mitigation notes
CVE7.1
NVDPending
Aug 20, 2026 CVE-2026-66672
Flatastic permits unauthenticated PHP object injection
Flatastic <= 2.0 allows an unauthenticated attacker to place attacker-controlled serialized data into an unsafe PHP deserialization path. Practical code execution depends on a usable gadget chain, but the CNA assigns high confidentiality, integrity and availability impact.
See mitigation notes
CVE9.8
NVDPending