Description
Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.
Published: 2025-12-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an “Insertion of Sensitive Information Into Sent Data” flaw in the WordPress plugin Shortcodes and extra features for Phlox theme auxin‑elements. An attacker who can exercise the plugin’s functionality can cause the plugin to embed sensitive data into outgoing responses, giving the attacker the ability to read protected information that should not be exposed to the public. This flaw impacts confidentiality and can expose confidential site data such as stored API keys, database credentials, or other configuration secrets that the plugin stores or references in its content structures.

Affected Systems

The issue affects the WordPress plugin Shortcodes and extra features for Phlox theme auxin‑elements, specifically all released versions up to and including 2.17.15. The vendor is averta, and the plugin is commonly installed in WordPress sites using the Phlox theme. Sites running any of these affected versions are potentially vulnerable.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. The EPSS score is less than 1%, signaling that the overall exploitation probability is low; the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a remotely-controllable request to the plugin, often via a public endpoint or shortcode rendering, enabling retrieval of hidden data. While the exploitation does not provide access to arbitrary code execution or privilege escalation, the exposure of sensitive data can lead to significant damage, especially if the leaked information is valuable or if an attacker follows up with further attacks.

Generated by OpenCVE AI on April 29, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Shortcodes and extra features for Phlox theme auxin‑elements plugin to version 2.17.16 or later, if a newer release is available.
  • If an update is not available or immediate update is not possible, deactivate or uninstall the plugin to stop the exposed data from being served.
  • Conduct a site-wide audit for any residual configuration or credential files that might have been exposed by previous plugin versions and remove or secure them accordingly.

Generated by OpenCVE AI on April 29, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12. Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.
Title WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.12 - Sensitive Data Exposure vulnerability WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.15 - Sensitive Data Exposure vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress
Vendors & Products Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.
Title WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.12 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Averta Shortcodes And Extra Features For Phlox Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:36:56.133Z

Reserved: 2025-10-24T14:26:55.389Z

Link: CVE-2025-63071

cve-icon Vulnrichment

Updated: 2025-12-09T15:47:55.942Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:12.980

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-63071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:30:10Z

Weaknesses