Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total12
Critical0
High1
Medium11
Reset
Showing 1-12 of 12 records
Threat Entry Updated 2026-01-13

CVE-2025-12379 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and ‘title_tag’ parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2025-12379

MEDIUM CVSS 6.4 2026-01-10
Threat Entry Updated 2026-01-08

CVE-2025-13215 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of draft posts that they should not have access to.

PLUGIN Auxin Elements

CVE-2025-13215

MEDIUM CVSS 5.3 2026-01-06
Threat Entry Updated 2025-05-22

CVE-2024-12588 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-12588

MEDIUM CVSS 6.4 2024-12-21
Threat Entry Updated 2025-05-22

CVE-2024-9545 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-9545

MEDIUM CVSS 6.4 2024-12-21
Threat Entry Updated 2025-05-22

CVE-2024-8486 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-8486

MEDIUM CVSS 6.4 2024-10-05
Threat Entry Updated 2025-05-29

CVE-2024-3517 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-3517

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-29

CVE-2024-3341 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-3341

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-29

CVE-2024-1533 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Requires Elementor and the Phlox theme to be installed.

PLUGIN Auxin Elements

CVE-2024-1533

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-29

CVE-2024-1396 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-1396

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-29

CVE-2024-1348 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-1348

MEDIUM CVSS 6.4 2024-05-02
Threat Entry Updated 2025-05-22

CVE-2023-7064 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.15.2 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated attackers able to upload a separate PHAR payload as an image file to inject a PHP Object, though the action itself is available to subscribers. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or…

PLUGIN Auxin Elements

CVE-2023-7064

HIGH CVSS 7.5 2024-05-02
Threat Entry Updated 2025-05-22

CVE-2024-1357 - Auxin Elements Plugin

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and date_type. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Auxin Elements

CVE-2024-1357

MEDIUM CVSS 6.4 2024-04-16
Scroll to top