Input validation vulnerability in Phlox 2.17.7

The Phlox theme for WordPress has a security issue known as Stored Cross-Site Scripting. This means that the theme is not properly protecting against harmful code being inserted into certain parts of the website. This vulnerability exists in all versions of the theme up to and including version 2.17.7. It allows attackers who are logged into the website with Contributor or higher level access to insert their own malicious code into pages. When a user visits these pages, the code will run and potentially cause harm.

Detected in:

Phlox fixed vulnerable versions: >= * <= 2.17.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.