PatchSiren

Themesflat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Themesflat CVE published 2026-04-08

CVE-2026-39500

A Stored XSS vulnerability was found in the themesflat-addons-for-elementor plugin. This issue affects themesflat-addons-for-elementor from n/a through <= 2.3.2. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The vulnerability exists due to improper neutralization of input during web page generation. An attacker with low privileges can exploit this vulnerability to inject malicious sc [truncated]