Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-57737
Averta LTD Shortcodes and extra features for Phlox theme — WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Cross Site Scripting (XSS) vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L R C L L L 6.5 .0022 12.0 —
AFFECTED
Product Versions Fixed
Shortcodes and extra features for Phlox theme unspecified 2.17.24
TIMELINE
Jun 25 Reserved by Patchstack
Jul 1 Published (CNA: Patchstack)
Oct 7 PATCH SHIPPED — CVE-2026-57737 (Averta LTD Shortcodes and extra features for Phlox theme). Fixed in Shortcodes and extra features for Phlox theme 2.17.24.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows DOM-Based XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.22.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 25, 2026 | Reserved | Reserved by Patchstack |
| July 1, 2026 | Published | Published (CNA: Patchstack) |
| October 7, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-57737 (Averta LTD Shortcodes and extra features for Phlox theme). Fixed in Shortcodes and extra features for Phlox theme 2.17.24. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Averta LTD | Shortcodes and extra features for Phlox theme | — | — | 2.17.24 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-57737 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.