PT-2026-31131 · Themesflat · Themesflat Addons For Elementor

Published

2026-04-08

·

Updated

2026-04-12

·

CVE-2026-39500

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Themesflat themesflat-addons-for-elementor versions through 2.3.2
Description The software contains a flaw due to improper input neutralization during web page generation, leading to a Cross-site Scripting issue. This allows for Stored XSS attacks.
Recommendations Update themesflat-addons-for-elementor to a version newer than 2.3.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-39500

Affected Products

Themesflat Addons For Elementor