Pricing
Case studies
Login
Start trial
Shortcodes and extra features for Phlox theme
averta
Developer
2.17.15
Latest version
90,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
2 present
17 patched
5 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget vulnerability
<= 2.17.2
03/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS vulnerability
<= 2.15.7
03/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode vulnerability
<= 2.15.7
03/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' vulnerability
<= 2.15.7
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.15.7
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode vulnerability
<= 2.15.7
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes vulnerability
<= 2.17.0
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget vulnerability
<= 2.17.13
02/02/2026
Unauthenticated Draft Posts Information Exposure vulnerability
<= 2.17.13
02/02/2026
Broken Access Control vulnerability
<= 2.17.15
27/12/2025
Sensitive Data Exposure vulnerability
<= 2.17.15
26/10/2025
Broken Access Control vulnerability
<= 2.17.4
31/01/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets vulnerability
<= 2.16.3
07/10/2024
Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer vulnerability
<= 2.17.5
16/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.15.5
16/04/2024
Broken Access Control vulnerability
<= 2.15.7
29/03/2024
Cross Site Scripting (XSS) vulnerability
<= 2.15.4
07/12/2023
Unauthenticated Local File Inclusion vulnerability
<= 2.14.0
15/11/2023
Reflected Cross-Site-Scripting (XSS) vulnerability
<= 2.9.7
20/06/2022