Sensitive Data Exposure in Phlox Theme Shortcodes by Auxin
CVE-2026-74008

5.3MEDIUM

What is CVE-2026-74008?

The Phlox theme versions up to 2.17.22 for WordPress are vulnerable to unauthenticated sensitive data exposure. This vulnerability allows attackers to potentially access sensitive information through shortcodes and additional features without requiring user authentication, posing a risk to users' data privacy. It is crucial for website administrators using this theme to apply necessary updates and mitigation strategies to protect against any potential exploitation.

Affected Version(s)

Shortcodes and extra features for Phlox theme <= 2.17.22

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.