Extension WordPress
Vulnérabilités Shortcodes and extra features for Phlox theme
Cette page rassemble les failles publiées pour Shortcodes and extra features for Phlox theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Shortcodes and extra features for Phlox theme
22 fiches
Shortcodes and extra features for Phlox theme <= 2.17.21 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.17.21
Non indiqué
01/07/2026
Shortcodes and extra features for Phlox theme <= 2.17.13 – Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and ‘title_tag’ parameters in all versions up to, and including, 2.17.13 due to insufficient input…
*-2.17.13
2.17.14
09/01/2026
Shortcodes and extra features for Phlox theme <= 2.17.13 – Unauthenticated Draft Posts Information Exposure
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This…
*-2.17.13
2.17.14
05/01/2026
Shortcodes and extra features for Phlox <= 2.17.14 – Missing Authorization
The Shortcodes and extra features for Phlox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.17.14. This makes it possible for authenticated attackers,…
*-2.17.14
Non indiqué
27/12/2025
Shortcodes and extra features for Phlox <= 2.17.13 – Unauthenticated Information Exposure
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration…
*-2.17.13
2.17.14
26/10/2025
Shortcodes and extra features for Phlox theme <= 2.17.4 – Missing Authorization
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.17.4. This makes it possible for…
*-2.17.4
2.17.5
31/01/2025
Shortcodes and extra features for Phlox theme <= 2.17.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping…
*-2.17.2
2.17.3
20/12/2024
Shortcodes and extra features for Phlox theme <= 2.17.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and…
*-2.17.0
2.17.1
20/12/2024
Shortcodes and extra features for Phlox theme <= 2.16.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to…
*-2.16.3
2.16.4
04/10/2024
Shortcodes and extra features for Phlox theme <= 2.17.5 – Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer'…
*-2.17.5
2.17.6
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping.…
*-2.15.7
2.15.8
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This…
*-2.15.7
2.15.8
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This…
*-2.15.5
2.15.6
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping…
*-2.15.7
2.15.8
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag'
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This…
*-2.15.7
2.15.8
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping…
*-2.15.7
2.15.8
15/04/2024
Shortcodes and extra features for Phlox theme <= 2.15.8 – Missing Authorization
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.15.8. This makes it possible for authenticated attackers, with subscriber-level…
*-2.15.5
2.15.8
29/03/2024
Shortcodes and extra features for Phlox theme <= 2.15.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.15.4 due to insufficient input sanitization and output escaping on…
*-2.15.4
2.15.5
06/12/2023
Shortcodes and extra features for Phlox theme <= 2.14.0 – Unauthenticated Local File Inclusion
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.14.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files…
*-2.14.0
2.15.0
15/11/2023
Shortcodes and extra features for Phlox theme <= 2.10.5 – PHP Objection Injection
The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject…
*-2.10.5
2.10.7
17/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.