CVE-2026-66673: WordPress Flatastic theme <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Affected Software
1 affected component
Flatastic theme<=2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Flatastic themeto a version that resolves this vulnerability.Fixed in 2.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges.
2
What user interaction is required for exploitation?
The CVSS vector indicates user interaction is required. An attacker would need a user to interact with a crafted request or content for the reflected XSS to execute.
3
What security impact can successful exploitation have?
The reported CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Successful XSS may affect a user’s browser session or actions performed in the affected site context.