Sensitive Data Exposure in Phlox Theme Shortcodes by Auxin
CVE-2026-74008
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-74008?
The Phlox theme versions up to 2.17.22 for WordPress are vulnerable to unauthenticated sensitive data exposure. This vulnerability allows attackers to potentially access sensitive information through shortcodes and additional features without requiring user authentication, posing a risk to users' data privacy. It is crucial for website administrators using this theme to apply necessary updates and mitigation strategies to protect against any potential exploitation.
Affected Version(s)
Shortcodes and extra features for Phlox theme <= 2.17.22
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program