📦 Shortcodes And Extra Features For Phlox Theme

by Averta

🔍 What is Shortcodes And Extra Features For Phlox Theme?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-37888

HIGH CVSS 7.6 May 17, 2024

This vulnerability allows unauthenticated attackers to perform path traversal attacks, leading to local file inclusion in WordPress sites using the Phlox theme's Shortcodes and extra features plugin. ...

CVE-2023-7064

HIGH CVSS 7.5 May 2, 2024

This vulnerability in the Phlox theme's Shortcodes plugin allows authenticated WordPress users with subscriber-level access to perform PHP object injection by exploiting insecure deserialization in th...

CVE-2024-50500

MEDIUM CVSS 4.3 Feb 3, 2025

This CVE describes a Missing Authorization vulnerability in the Shortcodes and extra features for Phlox theme WordPress plugin. It allows attackers to exploit incorrectly configured access control sec...

CVE-2024-12588

MEDIUM CVSS 6.4 Dec 21, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the Staff widget. The scripts execute whenever users ...

CVE-2024-8486

MEDIUM CVSS 6.4 Oct 5, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious JavaScript into website pages via the Modern Heading and Icon Picker widgets. The in...

CVE-2024-3517

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Phlox theme's Accordion Widget. The scripts are stored ...

CVE-2024-3341

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts via the 'aux_gmaps' shortcode in the Phlox theme plugin. The scripts are sto...

CVE-2024-1533

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious JavaScript into website pages via the Phlox theme's Shortcodes plugin. The injected ...