CVE-2025-8684 | Flatsome Plugin up to 3.20.0 on WordPress Shortcode cross site scripting
A vulnerability was found in Flatsome Plugin up to 3.20.0 on WordPress. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. Performing manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-8684. The attack is possible to be carried out remotely. No exploit exists.