CVE-2024-9545: Shortcodes and extra features for Phlox theme <= 2.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auxcontactbox and auxgmaps shortcodes in all versions up to, and including, 2.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9545?
CVE-2024-9545 is considered a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-9545?
To fix CVE-2024-9545, update the Phlox theme plugin for WordPress to version 2.16.5 or later.
What components are affected by CVE-2024-9545?
CVE-2024-9545 affects the aux_contact_box and aux_gmaps shortcodes in the Phlox theme plugin for WordPress.
What kind of attack can exploit CVE-2024-9545?
CVE-2024-9545 can be exploited through stored cross-site scripting attacks that can execute scripts in users' browsers.
Are all versions of the Phlox theme plugin vulnerable to CVE-2024-9545?
Yes, all versions of the Phlox theme plugin up to and including 2.16.4 are vulnerable to CVE-2024-9545.