Averta produces a modestly represented line of WordPress themes and slider plugins that extend site presentation and functionality, with a product portfolio that includes Master Slider, Depicter, and Auxin Portfolio components. Its vulnerability disclosures recur through a pattern of web-application weaknesses—cross-site scripting, CSRF, missing authorization checks, path traversal, and deserialization flaws—that are characteristic of PHP-based content-management extensions operating in user-controlled environments. The exposure spans both free and premium product variants and reflects the input-handling and permission-validation demands of plugins that interact with WordPress request flows and user input. Defenders maintaining WordPress installations should track this vendor's security updates for slider and portfolio functionality, particularly where admin panels or user-generated content is involved. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Averta over time
Signals from CVEs in this vendor scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57737MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. | Jul 1, 2026 | 6.5 | 33 | NO | NO |
CVE-2026-56014HIGH Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. | Jun 25, 2026 | 7.1 | 32 | NO | NO |
CVE-2023-37888CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclus | May 17, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-3359HIGH The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user | Dec 12, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-47359CRITICAL Cross-Site Request Forgery (CSRF) vulnerability in averta Depicter Slider depicter.This issue affects Depicter Slider: from n/a through <= 3.2.2. | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-68558MEDIUM Missing Authorization vulnerability in averta Depicter Slider depicter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: f | Jan 22, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-50500CRITICAL Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.T | Feb 3, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-32600CRITICAL Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5. | Apr 18, 2024 | 9.6 | 25 | NO | NO |
CVE-2023-47507CRITICAL Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5. | Dec 20, 2023 | 9.8 | 25 | NO | NO |
CVE-2022-1910MEDIUM The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected | Jul 11, 2022 | 6.1 | 25 | NO | YES |
Signals from CVEs in this vendor scope (56 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Averta.
Media articles that mention a CVE ID that affects a product developed by Averta — matched by CVE ID, not by vendor name.