CVE-2026-39500 is a Stored Cross-Site Scripting (XSS) vulnerability in Themesflat Addons for Elementor versions 2.3.2 and earlier, which allows improper neutralization of user input during web page generation. This vulnerability could enable authenticated attackers to inject malicious scripts that persist on the affected website and execute in the browsers of other users who view the compromised content. The vulnerability has been assigned a CVSS 3.1 score of 6.5 (Medium), indicating a moderate risk profile. It requires network access with low complexity and authenticated user privileges to exploit, though it does require user interaction. The impact is limited to confidentiality, integrity, and availability at the user level, with the attack scope extending beyond the vulnerable component. There is currently no evidence of active exploitation, and this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog or any active threat intelligence hot lists. The EPSS score of 0.00034 indicates very low probability of exploitation in the wild, and the FAUCET Risk Score of 35.0/100 suggests this is a lower-priority vulnerability for most organizations. Patching to versions beyond 2.3.2 is recommended but does not require emergency response prioritization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.3.2CPE match | cpe:2.3:a:themesflat:themesflat_addons_for_elementor:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.