Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS.

This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, which allows malicious scripts to run in browsers of visitors. Identified as CWE‑79, it is a DOM‑based cross‑site scripting flaw.

Affected Systems

The affected system is the WordPress plugin ‘Shortcodes and extra features for Phlox theme’ developed by Averta LTD. All installations of the plugin up through version 2.17.16 are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low but nonzero exploitation probability. The description notes DOM‑Based XSS arising when the plugin renders pages with unsanitized input. Any user who views affected content could potentially execute malicious scripts.

Generated by OpenCVE AI on August 3, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version that sanitizes input.
  • If an upgrade is not immediately possible, restrict the shortcode and extra feature inputs so that only administrators can submit them, or install an XSS‑blocking plugin to mitigate exploit attempts.
  • If the plugin cannot be disabled, configure the WordPress site to enforce a Content Security Policy that blocks inline scripts and disallows user‑supplied XSS vectors coming from the plugin.

Generated by OpenCVE AI on August 3, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress
Vendors & Products Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Title WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Averta Shortcodes And Extra Features For Phlox Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:51:05.073Z

Reserved: 2026-06-25T08:04:29.578Z

Link: CVE-2026-57737

cve-icon Vulnrichment

Updated: 2026-07-02T12:51:00.540Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')