Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2712 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. |
References
History
No history.
Subscriptions
Themerex
Subscribe
Addons
Subscribe
Aldo-gutenberg Wordpress Blog Theme
Subscribe
Amuli
Subscribe
Blabber
Subscribe
Bonkozoo Zoo
Subscribe
Briny-diving Wordpress Theme
Subscribe
Bugster-pests Control
Subscribe
Buzz Stone-magazine \& Blog
Subscribe
Chainpress
Subscribe
Chit Club-board Games
Subscribe
Coinpress-cryptocurrency Magazine \& Blog Wordpress Theme
Subscribe
Corredo Sport Event
Subscribe
Dronex-aerial Photography Services
Subscribe
Especio-food Gutenberg Theme
Subscribe
Fc United-football
Subscribe
Gloss Blog
Subscribe
Gridiron
Subscribe
Hallelujah-church
Subscribe
Heaven 11-multiskin Property Theme
Subscribe
Helion-agency \&portfolio
Subscribe
Hobo Digital Nomad Blog
Subscribe
Impacto Patronus Multi-landing
Subscribe
Justitia-multiskin Lawyer Theme
Subscribe
Kargo-freight Transport
Subscribe
Katelyn-gutenberg Wordpress Blog Theme
Subscribe
Kids Care
Subscribe
Kratz-digital Agency
Subscribe
Lingvico-language Learning School
Subscribe
Maxify-startup Blog
Subscribe
Meals And Wheels-food Truck
Subscribe
Modern Housewife-housewife And Family Blog
Subscribe
Mystik-esoterics
Subscribe
Nazareth-church
Subscribe
Nelson-barbershop \+ Tattoo Salon
Subscribe
Netmix-broadband \& Telecom
Subscribe
Ozeum-museum
Subscribe
Partiso Electioncampaign
Subscribe
Piqes-creative Startup \& Agency Wordpress Theme
Subscribe
Pixefy
Subscribe
Plumbing-repair\, Building \& Construction Wordpress Theme
Subscribe
Prider-pride Fest
Subscribe
Rare Radio
Subscribe
Renewal-plastic Surgeon Clinic
Subscribe
Rhodos-creative Corporate Wordpress Theme
Subscribe
Right Way
Subscribe
Rosalinda-vegetarian \& Health Coach
Subscribe
Rumble-single Fighter Boxer\, News\, Gym\, Store
Subscribe
Samadhi-buddhist
Subscribe
Savejulia Personal Fundraising Campaign
Subscribe
Scientia-public Library
Subscribe
Skydiving And Flying Company
Subscribe
Tacticool-shooting Range Wordpress Theme
Subscribe
Tantum-rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme
Subscribe
Tediss-soft Play Area\, Cafe \& Child Care Center
Subscribe
Topper Theme And Skins
Subscribe
Tornados
Subscribe
Vapester
Subscribe
Vihara-ashram\, Buddhist
Subscribe
Vixus-startup \/ Mobile Application
Subscribe
Wellspring Water Filter Systems
Subscribe
Yolox-startup Magazine \& Blog Wordpress Theme
Subscribe
Yottis-simple Portfolio
Subscribe
Yungen-digital\/marketing Agency
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:58:40.181Z
Reserved: 2020-03-09T00:00:00.000Z
Link: CVE-2020-10257
No data.
Status : Modified
Published: 2020-03-10T00:15:10.757
Modified: 2024-11-21T04:55:05.053
Link: CVE-2020-10257
No data.
OpenCVE Enrichment
No data.
EUVD