CVE-2025-69016: WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.15 - Broken Access Control vulnerability
Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69016?
The severity of CVE-2025-69016 is classified as a medium security risk due to its potential for unauthorized access.
How do I fix CVE-2025-69016?
To fix CVE-2025-69016, update the Shortcodes and extra features for Phlox theme to version 2.17.13 or later.
What problems does CVE-2025-69016 cause?
CVE-2025-69016 allows attackers to exploit incorrectly configured access control security levels in the affected plugin.
Which versions are affected by CVE-2025-69016?
CVE-2025-69016 affects Shortcodes and extra features for Phlox theme from versions n/a up to and including 2.17.12.
Is CVE-2025-69016 exploitable?
Yes, CVE-2025-69016 is exploitable if the plugin is not updated, allowing attackers to bypass authorization controls.