Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. | Insertion of Sensitive Information Into Sent Data vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.24. |
| Title | WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Data Exposure vulnerability | WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.24 - Sensitive Data Exposure vulnerability |
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Averta
Averta shortcodes And Extra Features For Phlox Theme Wordpress Wordpress wordpress |
|
| Vendors & Products |
Averta
Averta shortcodes And Extra Features For Phlox Theme Wordpress Wordpress wordpress |
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. | |
| Title | WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Data Exposure vulnerability | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-07T14:58:55.901Z
Reserved: 2026-08-14T10:16:11.319Z
Link: CVE-2026-74008
Updated: 2026-08-18T14:31:49.618Z
Status : Deferred
Published: 2026-08-18T15:17:09.437
Modified: 2026-10-07T16:18:50.147
Link: CVE-2026-74008
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:45:03Z
-
CWE-201
Insertion of Sensitive Information Into Sent Data