CVE-2023-40555 HIGH

CVE-2023-40555: WordPress Flatsome Theme <= 3.17.5 is vulnerable to PHP Object Injection

Vendor Ux-Themes
Product Flatsome | Multi-Purpose Responsive WooCommerce Theme
Weakness CWE-502 · Unsafe deserialization
Published December 20, 2023
Last update April 28, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.

Explanation of Vulnerability in Simple Terms

02Summary

Flatsome theme versions up to 3.17.5 contain a deserialization vulnerability in how they process untrusted data. An attacker can send a specially crafted request to execute arbitrary code on the site, read sensitive data, or disrupt service. No authentication or user interaction is required. The vulnerability affects the entire site and any connected systems.

What an attacker can do

03Attacker Capabilities

Execute code on the site, read sensitive data, or disrupt service without authentication.

Potential impact on your site

04Site Impact

Attackers can compromise your site, steal data, or take it offline without needing a user account.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 20, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE