Input validation vulnerability in Shortcodes and extra features for Phlox theme 2.14.0

The Phlox theme plugin for WordPress is vulnerable to a security issue called Local File Inclusion in all versions up to and including version 2.14.0. This security issue makes it possible for unauthenticated attackers to include and execute arbitrary files on the server. This can allow the execution of any type of code, such as PHP code, that is present in the included files. This could be used to bypass access controls, gain access to sensitive data, or execute code when images and other “safe” file types can be uploaded and included.

Detected in:

Shortcodes and extra features for Phlox theme open vulnerable versions: >= * <= 2.14.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.