Input validation vulnerability in Shortcodes and extra features for Phlox theme 2.16.3

The Phlox theme plugin for WordPress has a security issue that allows malicious code to be injected into web pages. This can be done by authenticated attackers with Contributor-level access or higher, through the use of Shortcodes and extra features such as the Modern Heading and Icon Picker widgets. The vulnerability is present in all versions up to and including 2.16.3, and is caused by a lack of proper input filtering and output protection.

Detected in:

Shortcodes and extra features for Phlox theme open vulnerable versions: >= * <= 2.16.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.