Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Published: 2020-03-09
Score: 9.8 Critical
EPSS: 66.6% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-2712 The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
History

No history.

Subscriptions

Themerex Addons Aldo-gutenberg Wordpress Blog Theme Amuli Blabber Bonkozoo Zoo Briny-diving Wordpress Theme Bugster-pests Control Buzz Stone-magazine \& Blog Chainpress Chit Club-board Games Coinpress-cryptocurrency Magazine \& Blog Wordpress Theme Corredo Sport Event Dronex-aerial Photography Services Especio-food Gutenberg Theme Fc United-football Gloss Blog Gridiron Hallelujah-church Heaven 11-multiskin Property Theme Helion-agency \&portfolio Hobo Digital Nomad Blog Impacto Patronus Multi-landing Justitia-multiskin Lawyer Theme Kargo-freight Transport Katelyn-gutenberg Wordpress Blog Theme Kids Care Kratz-digital Agency Lingvico-language Learning School Maxify-startup Blog Meals And Wheels-food Truck Modern Housewife-housewife And Family Blog Mystik-esoterics Nazareth-church Nelson-barbershop \+ Tattoo Salon Netmix-broadband \& Telecom Ozeum-museum Partiso Electioncampaign Piqes-creative Startup \& Agency Wordpress Theme Pixefy Plumbing-repair\, Building \& Construction Wordpress Theme Prider-pride Fest Rare Radio Renewal-plastic Surgeon Clinic Rhodos-creative Corporate Wordpress Theme Right Way Rosalinda-vegetarian \& Health Coach Rumble-single Fighter Boxer\, News\, Gym\, Store Samadhi-buddhist Savejulia Personal Fundraising Campaign Scientia-public Library Skydiving And Flying Company Tacticool-shooting Range Wordpress Theme Tantum-rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme Tediss-soft Play Area\, Cafe \& Child Care Center Topper Theme And Skins Tornados Vapester Vihara-ashram\, Buddhist Vixus-startup \/ Mobile Application Wellspring Water Filter Systems Yolox-startup Magazine \& Blog Wordpress Theme Yottis-simple Portfolio Yungen-digital\/marketing Agency
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:58:40.181Z

Reserved: 2020-03-09T00:00:00.000Z

Link: CVE-2020-10257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-10T00:15:10.757

Modified: 2024-11-21T04:55:05.053

Link: CVE-2020-10257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses