The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of draft posts that they should not have access to.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Averta
Averta shortcodes And Extra Features For Phlox Theme Wordpress Wordpress wordpress |
|
| Vendors & Products |
Averta
Averta shortcodes And Extra Features For Phlox Theme Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of draft posts that they should not have access to. | |
| Title | Shortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-06T06:36:25.702Z
Updated: 2026-01-06T14:34:11.678Z
Reserved: 2025-11-14T19:32:41.238Z
Link: CVE-2025-13215
Updated: 2026-01-06T14:34:08.065Z
Status : Received
Published: 2026-01-06T07:15:42.663
Modified: 2026-01-06T07:15:42.663
Link: CVE-2025-13215
No data.