CVE-2026-66672: WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Affected Software
1 affected component
WordPress Flatastic theme<=2.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to target a site using an affected Flatastic version.
2
What is the potential impact?
The listed severity vector indicates network-reachable exploitation with low attack complexity and no user interaction, with high potential impact to confidentiality, integrity, and availability.
3
Which versions are affected?
Flatastic versions 2.0 and earlier are identified as affected.