Impact
The Phlox theme for WordPress contains a stored cross‑site scripting flaw that allows an authenticated user with Contributor or higher privileges to inject arbitrary JavaScript into the page via the data‑caption attribute. The injected script is rendered and executed when any visitor loads the affected page, enabling attackers to hijack user sessions, exfiltrate data, deface content, or redirect users to malicious sites. The weakness is a classic input validation and output escaping failure cataloged as CWE‑79.
Affected Systems
All installations of the Phlox WordPress theme using version 2.17.7 or earlier are vulnerable. The affected product vendor is averta, and the issue arises in the theme’s handling of data‑caption attributes across all supported WordPress versions. Users with Contributor‑level access or higher can exploit this flaw.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 6.4, indicating moderate severity, and has an EPSS score of less than 1 %, suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with at least Contributor permissions, so lateral movement into content editing is a prerequisite. Once achieved, the attacker can embed malicious scripts that execute in any visitor’s browser, making the danger particularly high within high‑traffic sites.
OpenCVE Enrichment