Input validation vulnerability in Shortcodes and extra features for Phlox theme 2.16.4

The Phlox theme plugin for WordPress has a feature called Shortcodes, which allows for extra functionality. However, this feature has a security vulnerability known as Stored Cross-Site Scripting. This means that attackers with certain levels of access can inject harmful web scripts into pages, which will then run whenever someone views that page. This vulnerability affects all versions up to 2.16.4 of the plugin.

Detected in:

Shortcodes and extra features for Phlox theme open vulnerable versions: >= * <= 2.17.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.