{"error":0,"message":null,"data":{"name":"Shortcodes and extra features for Phlox theme","plugin":"auxin-elements","link":"https:\/\/wordpress.org\/plugins\/auxin-elements\/","latest":"1785592200","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"4d560b6314db82c8079a595c575ecbcccdef389908f9796860b3d4aefdad9d0a","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1910","name":"CVE-2022-1910","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1910","description":"[en] The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting","date":"2022-07-11"},{"id":"f90a7e427f3b045d568eb8ba995f77ea0effcb28","name":"WordPress Shortcodes and extra features for Phlox theme plugin <= 2.9.7 - Reflected Cross-Site-Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-9-7-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site-Scripting (XSS) vulnerability discovered by cydave in WordPress Shortcodes and extra features for Phlox theme plugin (versions <= 2.9.7).\nUpdate the WordPress Shortcodes and extra features for Phlox theme plugin to the latest available version (at least 2.9.8).","date":"2022-06-20"},{"id":"8afe1638-66fa-44c7-9d02-c81573193b47","name":"Shortcodes and extra features for Phlox theme &lt; 2.9.8 - Reflected Cross-Site-Scripting","link":"https:\/\/wpscan.com\/vulnerability\/8afe1638-66fa-44c7-9d02-c81573193b47","description":"The plugin does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting","date":null},{"id":"dbe51da949f9d55b1176c9c449c6c6aa2a44d07f","name":"Shortcodes and extra features for Phlox theme <= 2.9.7 - Reflected Cross-Site-Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-297-reflected-cross-site-scripting","description":"The Shortcodes and extra features for Phlox  WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting","date":"2022-06-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"ce542475eba571890f8c60de53a173649270aa6a3af190e0e1455a08842af6fa","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.10.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3359","name":"CVE-2022-3359","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3359","description":"[en] The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.","date":"2022-12-12"},{"id":"b0c2768594c8f6b67d6944ee8bf161b48ef4e019","name":"Shortcodes and extra features for Phlox theme <= 2.10.5 - PHP Objection Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2105-php-objection-injection","description":"The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2022-11-17"},{"id":"08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6","name":"Shortcodes and extra features for Phlox theme &lt;= 2.10.5 - PHP Objection Injection","link":"https:\/\/wpscan.com\/vulnerability\/08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6","description":"The plugin unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"924bfdf359f66b93b81e9a5641ec5ad098e5a68c1aa631beaba9f1d4043058f8","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"773bcbbcce1d168b1b02640317f42fe7edde62a2","name":"Shortcodes and extra features for Phlox theme <= 2.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-298-authenticated-contributor-stored-cross-site-scripting","description":"The  Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to stored Cross-Site Scripting via multiple Elementor Widgets in versions up to, and including, 2.9.8. This makes it possible for authenticated attackers with contributor-level permissions or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-07-12"}],"impact":[]},{"uuid":"e71c1600191e51172d073dbe66403facf91702a1be5070bee8c276c6f3957ca0","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-37888","name":"CVE-2023-37888","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-37888","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through 2.14.0.","date":"2024-05-17"},{"id":"2ecc7a8438d7238e1650775261d8f375c9ef388e","name":"WordPress  Shortcodes and extra features for Phlox theme Plugin  <= 2.14.0 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-phlox-core-elements-plugin-2-14-0-unauthenticated-local-file-inclusion-vulnerability","description":"No patched version is available. No reply from the vendor\nRafie Muhammad (Patchstack) discovered and reported this Local File Inclusion vulnerability in WordPress Shortcodes and extra features for Phlox theme Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has not been known to be fixed yet.","date":"2023-11-15"},{"id":"8fa43cfd2d8f76cb4fc8df17c0347511fe985e79","name":"Shortcodes and extra features for Phlox theme <= 2.14.0 - Unauthenticated Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2140-unauthenticated-local-file-inclusion","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.14.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2023-11-15"},{"id":"2a7cbd8d-83de-43b1-ae8c-159d56104bba","name":"Shortcodes and extra features for Phlox theme &lt; 2.15.0 - Unauthenticated Local File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/2a7cbd8d-83de-43b1-ae8c-159d56104bba","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.14.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other &ldquo;safe&rdquo; file types can be uploaded and included.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"l","a":"l","score":"7.6","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"low","a":"low","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ff7352f91c0c5ee1fef093b1c14b0d4a23ae576de213cab5165143a020720412","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-50368","name":"CVE-2023-50368","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-50368","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through 2.15.2.","date":"2023-12-14"},{"id":"4027409f212761888bd13d0d6f38b8927089c60a","name":"Shortcodes and extra features for Phlox theme <= 2.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2152-authenticated-contributor-stored-cross-site-scripting","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.15.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-06"},{"id":"e7afcc9f0ff3482d8d6450d626159fa1b8f5bdd0","name":"WordPress  Shortcodes and extra features for Phlox theme Plugin  <= 2.15.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-15-2-cross-site-scripting-xss-vulnerability","description":"No patched version is available. This plugin has been closed as of December 7, 2023 and is not available for download. This closure is temporary, pending a full review.\nNG\u00d4 THI\u00caN AN (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortcodes and extra features for Phlox theme Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has not been known to be fixed yet.","date":"2023-12-07"},{"id":"4ece057c-746e-4448-82b0-d790afb34960","name":"Shortcodes and extra features for Phlox theme &lt;= 2.15.4 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/4ece057c-746e-4448-82b0-d790afb34960","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"bcc2f3bc8101d06de6728ca1ea50d4657f76a866106d8447b69a368463b2bd8a","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-31099","name":"CVE-2024-31099","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31099","description":"[en] Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through 2.15.7.","date":"2024-04-01"},{"id":"81db0d559444d8ad549df9cfc53e475435a48651","name":"WordPress  Shortcodes and extra features for Phlox theme Plugin    <= 2.15.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-phlox-core-elements-plugin-2-15-5-broken-access-control-vulnerability","description":"No patched version is available. Reported to the WP review team on March 7, 2024.\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Shortcodes and extra features for Phlox theme Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"b08e5c665a81650312d6212dd417ccf74466cf70","name":"Shortcodes and extra features for Phlox theme <= 2.15.8 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-missing-authorization","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.15.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2024-03-29"},{"id":"5c6faa84-f33d-4d3c-8397-1e4add1f7ff3","name":"Shortcodes and extra features for Phlox theme &lt;= 2.15.5 - Missing Authorization","link":"https:\/\/wpscan.com\/vulnerability\/5c6faa84-f33d-4d3c-8397-1e4add1f7ff3","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.15.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c77dab30657b44b6e764aa82075ebcf0d8fdc0a0db6a411ff1701f17a216e9b7","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3517","name":"CVE-2024-3517","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3517","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"8b10d5f9495d8bd0717d421ba10cfabf726cc04e","name":"Shortcodes and extra features for Phlox theme <= 2.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting-via-accordion-widget","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"},{"id":"db4be506530420d089556f9d4bdab3c2cb8536e7","name":"WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.15.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-15-5-authenticated-contributor-stored-cross-site-scripting-via-accordion-widget-vulnerability","description":"<p>WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.15.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 2.15.5<\/p>","date":"2024-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"927dce1242ea9aa37bb45db75e1ce353f8b82a9c7ac3ca73437d9be6ce86fb75","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1357","name":"CVE-2024-1357","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1357","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and date_type. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-16"},{"id":"83ea9882d4c24900bce3e639af06e0c8a84d3673","name":"Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting-via-aux-timeline-shortcode","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and date_type. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"45d23ab86706b562088cfd55aea19bf93a189549d79a54e826d921a5896ff077","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1533","name":"CVE-2024-1533","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1533","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Requires Elementor and the Phlox theme to be installed.","date":"2024-05-02"},{"id":"18787edfdaa2ba7a95b58194b74d4f2014f61948","name":"Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Requires Elementor and the Phlox theme to be installed.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"97f37a0b53b3bf4e3fbbc23a56461db99a69de858f45b355267166a94be0f96e","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1348","name":"CVE-2024-1348","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1348","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"ae3ce11b153c6384d95b881a837cdbdedb166300","name":"Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting-via-custom-js","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"85be48e92f0acae59ff8fd08d9e7578d0b1081593c2a79db5888bf2aef9f5f84","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3341","name":"CVE-2024-3341","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3341","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"cfb5cc6bc27da147e3968ad6e3b7740cadeae757","name":"Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting-via-aux-gmaps-shortcode","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"25ce2076e515f6624a54cb388cc45944e47ad710e5579f8716ac6d6c06885ce9","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1396","name":"CVE-2024-1396","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1396","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title_tag\u2019 parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"a7dfa7738afba5202940b7a118b84fe4f1bac13d","name":"Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2155-authenticated-contributor-stored-cross-site-scripting-via-title-tag","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title_tag\u2019 parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"efcc9ed0bd41c964e03c60f16dfc0f03d86f847bebb2fcf46007b2085ca365e4","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-7064","name":"CVE-2023-7064","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-7064","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.15.2 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated attackers able to upload a separate PHAR payload as an image file to inject a PHP Object, though the action itself is available to subscribers. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-05-02"},{"id":"a70f2c46aa27f3ba6f751c38dd270c17d275c077","name":"Shortcodes and extra features for Phlox theme <= 2.17.5 - Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2152-authenticated-subscriber-php-object-injection-via-auxin-template-control-importer","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated attackers able to upload a separate PHAR payload as an image file to inject a PHP Object, though the action itself is available to subscribers. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-04-15"},{"id":"35513cb59e5b39b5563c0d08fb8def34ad86f642","name":"WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.15.2 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-15-2-authenticated-subscriber-php-object-injection-via-auxin-template-control-importer-vulnerability","description":"<p>WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.15.2 is vulnerable to PHP Object Injection<\/p><p>Affected Version <= 2.15.2<\/p>","date":"2024-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.5","severity":"h","exploitable":"1.6","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.5","severity":"high","av":"network","ac":"high","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.6","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4989c5f3f39941558aa5288de5955bcf7a68699893a1f6b6e44d682bca2a376e","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.16.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.16.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8486","name":"CVE-2024-8486","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8486","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-05"},{"id":"ff6e4282ebd4491379789d586088c91496aee5d5","name":"Shortcodes and extra features for Phlox theme <= 2.16.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2163-authenticated-contributor-stored-cross-site-scripting-via-modern-heading-and-icon-picker-widgets","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-04"},{"id":"c65924e8df977498b2f5e785789b8dd49c5cd80e","name":"WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.16.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-16-3-authenticated-contributor-stored-cross-site-scripting-via-modern-heading-and-icon-picker-widgets-vulnerability","description":"<p>WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.16.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Shortcodes and extra features for Phlox theme<\/p><p>Link: https:\/\/wordpress.org\/plugins\/auxin-elements\/#developers<\/p><p>Affected Version <= 2.16.3<\/p><p>Fixed in version 2.16.4 <\/p>","date":"2024-10-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e4f74db91d4abc06ef42c8ec96924a25be416bf3ea388aa35380afcab42d429c","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9545","name":"Shortcodes and extra features for Phlox theme <= 2.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9545","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"b56cce4544e75397552d99d28963759d83b42d0b","name":"Shortcodes and extra features for Phlox theme <= 2.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2164-authenticated-contributor-stored-cross-site-scripting-via-aux-contact-box-and-aux-gmaps-shortcodes","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-20"},{"id":"EUVD-2024-50445","name":"EUVD-2024-50445","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50445","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"78cf3b2eac061612fdb5b038837b783334f5cb6dd9b1cf5b8e22d4caed793e2f","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12588","name":"CVE-2024-12588","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12588","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-21"},{"id":"152a79edf5089fcf131f420d472b49c0f7db744b","name":"Shortcodes and extra features for Phlox theme <= 2.17.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2164-authenticated-contributor-stored-cross-site-scripting-via-staff-widget","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-20"},{"id":"EUVD-2024-50979","name":"EUVD-2024-50979","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50979","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e82cee658de1014a7858442887e70b922d9f879567e479179a33509d17ce0d4e","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50500","name":"CVE-2024-50500","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50500","description":"[en] Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through <= 2.17.4.","date":"2025-02-03"},{"id":"cdd7b1fc19c05b45a857d37bd6cd0b5b7c5bafca","name":"WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.17.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/auxin-elements\/vulnerability\/wordpress-phlox-core-elements-plugin-2-17-2-broken-access-control-vulnerability","description":"<p>WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.17.2 is vulnerable to Broken Access Control<\/p><p>Software: Shortcodes and extra features for Phlox theme<\/p><p>Affected Version <= 2.17.2<\/p><p>CVE: CVE-2024-50500<\/p>","date":"2025-01-31"},{"id":"80f403189bc5e9e31612126e8ee1f00c38396d9e","name":"Shortcodes and extra features for Phlox theme <= 2.17.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-2172-missing-authorization","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.17.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2025-01-31"},{"id":"EUVD-2024-44627","name":"EUVD-2024-44627","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-44627","description":"Missing Authorization vulnerability in By Averta Shortcodes and extra features for Phlox theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortcodes and extra features for Phlox theme: from n\/a through 2.17.2.","date":"2025-02-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"46bc4d81217f913e32d17dbe32a80052f07fa23f6f9ac94a146ab380cf9b0445","name":"Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.15 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.15","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-63071","name":"CVE-2025-63071","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-63071","description":"[en] Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through <= 2.17.15.","date":"2025-12-09"},{"id":"e5fa7710151dd48afcbf9e1d2664497b08b2e6d4","name":"Shortcodes and extra features for Phlox <= 2.17.13 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-21712-unauthenticated-information-exposure","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2025-10-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d279fbd9b772dfb0c680d3eda3de9b9ec901fced2c5ff92d75dd1f0ebd5e18f9","name":"Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.15 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.15","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-69016","name":"CVE-2025-69016","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-69016","description":"[en] Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n\/a through <= 2.17.15.","date":"2025-12-30"},{"id":"b9bbddd026fdd21f474537704f41831ae56fb55c","name":"Shortcodes and extra features for Phlox <= 2.17.14 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-21714-missing-authorization","description":"The Shortcodes and extra features for Phlox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.17.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2025-12-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"48fb6ed7d81b8b843fc281cf077bc8311d999af51d30e9cb8df8724d66542738","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13215","name":"CVE-2025-13215","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13215","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of draft posts that they should not have access to.","date":"2026-01-06"},{"id":"15cc87a65fb265b186d48f10d4c7661431c3790a","name":"Shortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-21713-unauthenticated-draft-posts-information-exposure","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of draft posts that they should not have access to.","date":"2026-01-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c35f2461cedb05f7922086cafead26fb86dd2e2919bec5addf7f216bb421838e","name":"Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12379","name":"CVE-2025-12379","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12379","description":"[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and \u2018title_tag\u2019 parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-01-10"},{"id":"050fcaa307f047ad8f788eef684546ee2529a6c8","name":"Shortcodes and extra features for Phlox theme <= 2.17.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-21713-authenticated-contributor-stored-cross-site-scripting-via-modern-heading-widget","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and \u2018title_tag\u2019 parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-01-09"},{"id":"EUVD-2026-1845","name":"EUVD-2026-1845","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-1845","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and \u2018title_tag\u2019 parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-01-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ec3cf2b1a54fac638f3495adae2c6fe9c818ac8e8036334ddf9ae61f399b1650","name":"Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.21 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.21","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-57737","name":"CVE-2026-57737","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57737","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS.\n\nThis issue affects Shortcodes and extra features for Phlox theme: from n\/a through 2.17.16.","date":"2026-07-01"},{"id":"7b967ab12c78317b6850415ec33601778f70284f","name":"Shortcodes and extra features for Phlox theme <= 2.17.21 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/auxin-elements\/shortcodes-and-extra-features-for-phlox-theme-21721-authenticated-contributor-stored-cross-site-scripting","description":"The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2eb20f4e9e840c3595ac0265523afa6806f0ad1726e7ff66c865d0d98a68f9ca","name":"Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.22 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.17.22","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-74008","name":"CVE-2026-74008","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74008","description":"[en] Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.","date":"2026-08-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1787203030"}