Executive brief
A security vulnerability exists in the Phlox theme's companion plugin, which provides layout and design features for WordPress websites. An attacker with basic contributor-level access could inject malicious scripts into the site's pages. If a site visitor or administrator views the affected content, the script could execute in their browser, potentially leading to unauthorized actions, data theft, or redirection to malicious websites.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the 'Shortcodes and extra features for Phlox theme' (auxin-elements) plugin for WordPress. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Contributor' or higher privileges can inject malicious JavaScript payloads that execute in the context of a victim's browser session. Exploitation requires user interaction, such as a victim viewing a specifically crafted page or clicking a malicious link. As of the advisory date, no official patch has been released, and the vulnerability affects all versions up to and including 2.17.16.
Affected products
- Averta LTD Shortcodes and extra features for Phlox theme (auxin-elements) <= 2.17.16
Timeline
- 2026-02-10: other: Reported by researcher timomangcut
- 2026-07-01: advisory: Published by Patchstack and NVD