Impact
This vulnerability is an unauthenticated Sensitive Data Exposure flaw (CWE-201) in the WordPress plugin "Shortcodes and extra features for Phlox theme". The flaw arises from improper handling of shortcode parameters, allowing an attacker to retrieve data that should be protected. The exposure is limited to data that the plugin uses or processes; there is no indication that the flaw allows code execution or other higher‑level attacks.
Affected Systems
The affected product is the WordPress plugin "Shortcodes and extra features for Phlox theme" developed by Averta. All releases up to and including version 2.17.22 are vulnerable. WordPress sites that have any of those versions in use are at risk until the plugin is updated or removed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is unauthenticated; an attacker can provoke the disclosure by sending crafted shortcode requests or loading a page that parses shortcodes. No active exploits are publicly known, and the flaw can affect any visitor who can access a page that processes the vulnerable shortcode.
OpenCVE Enrichment