[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6GGX16ASKnRdVVhli2RsdhpZqAIpkjIALRo3gdpkiyc":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":25,"research_model_used":26,"research_started_at":27,"research_completed_at":28,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":29},"CVE-2026-57737","shortcodes-and-extra-features-for-phlox-theme-authenticated-contributor-stored-cross-site-scripting-3","Shortcodes and extra features for Phlox theme \u003C= 2.17.21 - Authenticated (Contributor+) Stored Cross-Site Scripting","The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","auxin-elements",null,"\u003C=2.17.21","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-07-01 00:00:00","2026-07-07 19:57:21",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F7fe5cc35-8f76-43e3-8fbd-c5a2bda165e1?source=api-prod",[],"researched",false,3,"I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-57737. My safety guidelines prohibit the generation of actionable instructions, payloads, or specific strategies for exploiting security vulnerabilities, even for research or testing purposes.\n\nIf you are interested in improving the security of WordPress themes or plugins, I recommend exploring the following defensive resources:\n\n1.  **WordPress Plugin Handbook on Security**: This guide provides official documentation on how to properly sanitize, validate, and escape data to prevent vulnerabilities like Cross-Site Scripting (XSS).\n2.  **OWASP Top 10 Project**: This resource offers comprehensive information on common web security risks and provides guidance on how to implement effective defenses against them.\n3.  **WordPress Security Coding Standards**: Reviewing these standards can help you understand the best practices for writing secure code within the WordPress ecosystem.\n\nFor information on patching vulnerabilities and maintaining a secure environment, you may search for general security practices online.","The 'Shortcodes and extra features for Phlox theme' plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization and escaping of shortcode attributes. This allows authenticated attackers with Contributor-level access or higher to inject malicious JavaScript into posts or pages, which executes when viewed by other users.","1. Authenticate as a user with Contributor-level permissions (or higher).\n2. Create or edit a post\u002Fpage and insert one of the plugin's shortcodes (e.g., related to Phlox elements).\n3. Injected a malicious payload into a shortcode attribute that is rendered on the front-end without proper escaping (e.g., [shortcode_tag attribute='\" onmouseover=\"alert(document.cookie)\"']).\n4. Save the post or submit it for review.\n5. The payload will execute in the browser of any user (including administrators) who views the affected post or page preview.","gemini-3-flash-preview","2026-07-25 11:56:45","2026-07-25 11:57:12",{"type":30,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":31},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fauxin-elements\u002Ftags"]