WordPress security by component
flatastic
flatastic is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.8.
Theme slug:
flatasticLatest vulnerability
CVE-2026-66673: Flatastic permits unauthenticated cross-site scripting
Flatastic <= 2.0 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
| Safe version |
|
||
|---|---|---|---|
| Aug 20, 2026 |
CVE-2026-66673
Flatastic permits unauthenticated cross-site scripting
Flatastic <= 2.0 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Aug 20, 2026 |
CVE-2026-66672
Flatastic permits unauthenticated PHP object injection
Flatastic <= 2.0 allows an unauthenticated attacker to place attacker-controlled serialized data into an unsafe PHP deserialization path. Practical code execution depends on a usable gadget chain, but the CNA assigns high confidentiality, integrity and availability impact.
|
See mitigation notes |
CVE9.8
NVDPending
|