Impact
The vulnerability is an improper neutralization of user input during web page generation, which allows malicious scripts to run in browsers of visitors. Identified as CWE‑79, it is a DOM‑based cross‑site scripting flaw.
Affected Systems
The affected system is the WordPress plugin ‘Shortcodes and extra features for Phlox theme’ developed by Averta LTD. All installations of the plugin up through version 2.17.16 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low but nonzero exploitation probability. The description notes DOM‑Based XSS arising when the plugin renders pages with unsanitized input. Any user who views affected content could potentially execute malicious scripts.
OpenCVE Enrichment