Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS.

This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, allowing malicious scripts to run in the browsers of visitors. This standard input validation flaw, identified as CWE‑79, enables DOM‑based cross‑site scripting that can compromise the confidentiality and session integrity of users who view affected content.

Affected Systems

The affected system is the WordPress plugin ‘Shortcodes and extra features for Phlox theme’ developed by Averta LTD. All installations of the plugin up through version 2.17.16 are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 demonstrates moderate severity, while the EPSS score of less than 1 % indicates a very low but nonzero exploitation probability. The likely attack vector is DOM‑based XSS page rendered by the plugin with unsanitized input. An attacker who can configure the plugin could embed malicious code, and any user who views the affected page would execute the payload.

Generated by OpenCVE AI on July 21, 2026 at 13:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version that sanitizes input.
  • If an upgrade is not immediately possible, restrict the shortcode and extra feature inputs so that only administrators can accept user‑site‑wide XSS filtering solution or install an XSS‑blocking plugin to mitigate exploit attempts.
  • If the plugin cannot be disabled, configure the WordPress site to enforce a Content Security Policy that blocks inline scripts and disallows user‑supplied XSS vectors coming from the plugin.

Generated by OpenCVE AI on July 21, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress
Vendors & Products Averta
Averta shortcodes And Extra Features For Phlox Theme
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Title WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Averta Shortcodes And Extra Features For Phlox Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:51:05.073Z

Reserved: 2026-06-25T08:04:29.578Z

Link: CVE-2026-57737

cve-icon Vulnrichment

Updated: 2026-07-02T12:51:00.540Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')