Extension WordPress

Vulnérabilités Shortcodes and extra features for Phlox theme

Cette page rassemble les failles publiées pour Shortcodes and extra features for Phlox theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.

22Vulnérabilités
1Critiques
20Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Shortcodes and extra features for Phlox theme

22 fiches

CVE-2026-57737 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.21 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.17.21

Correctif

Non indiqué

Publication

01/07/2026

CVE-2025-12379 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.13 – Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and ‘title_tag’ parameters in all versions up to, and including, 2.17.13 due to insufficient input…

Versions affectées

*-2.17.13

Correctif

2.17.14

Publication

09/01/2026

CVE-2025-13215 Moyenne · 5,3
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.13 – Unauthenticated Draft Posts Information Exposure

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This…

Versions affectées

*-2.17.13

Correctif

2.17.14

Publication

05/01/2026

CVE-2025-69016 Moyenne · 4,3
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox <= 2.17.14 – Missing Authorization

The Shortcodes and extra features for Phlox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.17.14. This makes it possible for authenticated attackers,…

Versions affectées

*-2.17.14

Correctif

Non indiqué

Publication

27/12/2025

CVE-2025-63071 Moyenne · 5,3
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox <= 2.17.13 – Unauthenticated Information Exposure

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration…

Versions affectées

*-2.17.13

Correctif

2.17.14

Publication

26/10/2025

CVE-2024-12588 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping…

Versions affectées

*-2.17.2

Correctif

2.17.3

Publication

20/12/2024

CVE-2024-9545 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and…

Versions affectées

*-2.17.0

Correctif

2.17.1

Publication

20/12/2024

CVE-2024-8486 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.16.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to…

Versions affectées

*-2.16.3

Correctif

2.16.4

Publication

04/10/2024

CVE-2023-7064 Élevée · 7,5
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.17.5 – Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer'…

Versions affectées

*-2.17.5

Correctif

2.17.6

Publication

15/04/2024

CVE-2024-1348 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.15.7

Correctif

2.15.8

Publication

15/04/2024

CVE-2024-1533 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.15.7

Correctif

2.15.8

Publication

15/04/2024

CVE-2024-3517 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.15.5

Correctif

2.15.6

Publication

15/04/2024

CVE-2024-1357 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping…

Versions affectées

*-2.15.7

Correctif

2.15.8

Publication

15/04/2024

CVE-2024-1396 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag'

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.15.7

Correctif

2.15.8

Publication

15/04/2024

CVE-2024-3341 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping…

Versions affectées

*-2.15.7

Correctif

2.15.8

Publication

15/04/2024

CVE-2024-31099 Moyenne · 4,3
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.8 – Missing Authorization

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.15.8. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-2.15.5

Correctif

2.15.8

Publication

29/03/2024

CVE-2023-50368 Moyenne · 6,4
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.15.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.15.4 due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.15.4

Correctif

2.15.5

Publication

06/12/2023

CVE-2023-37888 Critique · 9,8
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.14.0 – Unauthenticated Local File Inclusion

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.14.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files…

Versions affectées

*-2.14.0

Correctif

2.15.0

Publication

15/11/2023

CVE-2022-3359 Élevée · 7,2
Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme <= 2.10.5 – PHP Objection Injection

The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject…

Versions affectées

*-2.10.5

Correctif

2.10.7

Publication

17/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités