plugin

Auxin Elements Vulnerabilities

43 known security issues reported for the Auxin Elements WordPress plugin. Most recent disclosed Jul 1, 2026.

1 critical 2 high 19 medium

Running Auxin Elements on your site? Check whether your installed version is affected.

Scan your site free

Shortcodes and extra features for Phlox theme <= 2.17.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 2.17.21
Fix:
No patched version reported
Disclosed:
Jul 1, 2026

CVE-2026-57737 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.14

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and ‘title_tag’ parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

Affected:
up to 2.17.14
Fixed in:
2.17.14
Disclosed:
Jan 10, 2026

CVE-2025-12379 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading Widget

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a combination of the 'tag' and ‘title_tag’ parameters in all versions up to, and including, 2.17.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.17.13
Fixed in:
2.17.14
Disclosed:
Jan 9, 2026

CVE-2025-12379 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.14

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titl...

Affected:
up to 2.17.14
Fixed in:
2.17.14
Disclosed:
Jan 6, 2026

CVE-2025-13215 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information Exposure

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.17.13 via the auxels_ajax_search due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract titles of...

CVSS:
5.3
Affected:
up to 2.17.13
Fixed in:
2.17.14
Disclosed:
Jan 5, 2026

CVE-2025-13215 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.12 (unfixed)

unknown

[en] Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

Affected:
up to 2.17.12
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-69016 on NVD →

Shortcodes and extra features for Phlox <= 2.17.14 - Missing Authorization

medium

The Shortcodes and extra features for Phlox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.17.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.17.14
Fix:
No patched version reported
Disclosed:
Dec 27, 2025

CVE-2025-69016 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] <= 2.17.12 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

Affected:
up to 2.17.12
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63071 on NVD →

Shortcodes and extra features for Phlox <= 2.17.13 - Unauthenticated Information Exposure

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.13. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.17.13
Fixed in:
2.17.14
Disclosed:
Oct 26, 2025

CVE-2025-63071 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.5

unknown

[en] Missing Authorization vulnerability in By Averta Shortcodes and extra features for Phlox theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.2.

Affected:
up to 2.17.5
Fixed in:
2.17.5
Disclosed:
Feb 3, 2025

CVE-2024-50500 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.4 - Missing Authorization

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.17.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized...

CVSS:
4.3
Affected:
up to 2.17.4
Fixed in:
2.17.5
Disclosed:
Jan 31, 2025

CVE-2024-50500 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.3

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Dec 21, 2024

CVE-2024-12588 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.17.2
Fixed in:
2.17.3
Disclosed:
Dec 20, 2024

CVE-2024-12588 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

CVSS:
6.4
Affected:
up to 2.17.0
Fixed in:
2.17.1
Disclosed:
Dec 20, 2024

CVE-2024-9545 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.16.4

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for...

Affected:
up to 2.16.4
Fixed in:
2.16.4
Disclosed:
Oct 5, 2024

CVE-2024-8486 on NVD →

Shortcodes and extra features for Phlox theme <= 2.16.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authe...

CVSS:
6.4
Affected:
up to 2.16.3
Fixed in:
2.16.4
Disclosed:
Oct 4, 2024

CVE-2024-8486 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.0

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0.

Affected:
up to 2.15.0
Fixed in:
2.15.0
Disclosed:
May 17, 2024

CVE-2023-37888 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.6

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.15.2 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authentic...

Affected:
up to 2.17.6
Fixed in:
2.17.6
Disclosed:
May 2, 2024

CVE-2023-7064 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
May 2, 2024

CVE-2024-1396 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
May 2, 2024

CVE-2024-3341 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
May 2, 2024

CVE-2024-1348 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor acce...

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
May 2, 2024

CVE-2024-1533 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.6

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

Affected:
up to 2.15.6
Fixed in:
2.15.6
Disclosed:
May 2, 2024

CVE-2024-3517 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and date...

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
Apr 16, 2024

CVE-2024-1357 on NVD →

Shortcodes and extra features for Phlox theme <= 2.17.5 - Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer

high

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 via deserialization of untrusted input from the vulnerable 'id' parameter in the 'auxin_template_control_importer' function. This makes it possible for authenticated...

CVSS:
7.5
Affected:
up to 2.17.5
Fixed in:
2.17.6
Disclosed:
Apr 15, 2024

CVE-2023-7064 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or...

CVSS:
6.4
Affected:
up to 2.15.7
Fixed in:
2.15.8
Disclosed:
Apr 15, 2024

CVE-2024-1533 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor ac...

CVSS:
6.4
Affected:
up to 2.15.7
Fixed in:
2.15.8
Disclosed:
Apr 15, 2024

CVE-2024-1348 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_gmaps' shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...

CVSS:
6.4
Affected:
up to 2.15.7
Fixed in:
2.15.8
Disclosed:
Apr 15, 2024

CVE-2024-3341 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping on user supplied attributes such as thumb_mode and date_type...

CVSS:
6.4
Affected:
up to 2.15.7
Fixed in:
2.15.8
Disclosed:
Apr 15, 2024

CVE-2024-1357 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag'

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-...

CVSS:
6.4
Affected:
up to 2.15.7
Fixed in:
2.15.8
Disclosed:
Apr 15, 2024

CVE-2024-1396 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor acces...

CVSS:
6.4
Affected:
up to 2.15.5
Fixed in:
2.15.6
Disclosed:
Apr 15, 2024

CVE-2024-3517 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.8

unknown

[en] Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.7.

Affected:
up to 2.15.8
Fixed in:
2.15.8
Disclosed:
Apr 1, 2024

CVE-2024-31099 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.8 - Missing Authorization

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 2.15.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.15.5
Fixed in:
2.15.8
Disclosed:
Mar 29, 2024

CVE-2024-31099 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.15.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2.

Affected:
up to 2.15.5
Fixed in:
2.15.5
Disclosed:
Dec 14, 2023

CVE-2023-50368 on NVD →

Shortcodes and extra features for Phlox theme <= 2.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.15.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.15.4
Fixed in:
2.15.5
Disclosed:
Dec 6, 2023

CVE-2023-50368 on NVD →

Shortcodes and extra features for Phlox theme <= 2.14.0 - Unauthenticated Local File Inclusion

critical

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.14.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. Thi...

CVSS:
9.8
Affected:
up to 2.14.0
Fixed in:
2.15.0
Disclosed:
Nov 15, 2023

CVE-2023-37888 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.10.7

unknown

[en] The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Affected:
up to 2.10.7
Fixed in:
2.10.7
Disclosed:
Dec 12, 2022

CVE-2022-3359 on NVD →

Shortcodes and extra features for Phlox theme <= 2.10.5 - PHP Objection Injection

high

The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable...

CVSS:
7.2
Affected:
up to 2.10.5
Fixed in:
2.10.7
Disclosed:
Nov 17, 2022

CVE-2022-3359 on NVD →

Shortcodes and extra features for Phlox theme <= 2.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to stored Cross-Site Scripting via multiple Elementor Widgets in versions up to, and including, 2.9.8. This makes it possible for authenticated attackers with contributor-level permissions or above to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 2.9.8
Fixed in:
2.9.14
Disclosed:
Jul 12, 2022

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.9.14

unknown

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to stored Cross-Site Scripting via multiple Elementor Widgets in versions up to, and including, 2.9.8. This makes it possible for authenticated attackers with contributor-level permissions or above to inject arbitrary web scripts in p...

Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Jul 12, 2022

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.9.8

unknown

[en] The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Jul 11, 2022

CVE-2022-1910 on NVD →

Shortcodes and extra features for Phlox theme <= 2.9.7 - Reflected Cross-Site-Scripting

medium

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVSS:
5.4
Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Jun 20, 2022

CVE-2022-1910 on NVD →

Shortcodes and extra features for Phlox theme [auxin-elements] < 2.17.1

unknown
Affected:
up to 2.17.1
Fixed in:
2.17.1

CVE-2024-9545 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database