Information Exposure Vulnerability in Phlox Theme Plugin for WordPress
CVE-2025-13215
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 January 2026
What is CVE-2025-13215?
The Phlox theme plugin for WordPress, specifically the auxels_ajax_search feature, allows unauthenticated users to exploit the plugin due to inadequate restrictions. This vulnerability enables attackers to access and extract titles of draft posts that should remain confidential, thereby posing a significant risk to user privacy and content integrity. It is crucial for users to update their plugins to mitigate this risk.
Affected Version(s)
Shortcodes and extra features for Phlox theme 0 <= 2.17.13