CVE-2020-10257
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2020
Last modified:
21/07/2021
Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:ozeum-museum:*:*:*:*:*:wordpress:*:* | 1.0.2 (excluding) | |
| cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:chit_club-board_games:*:*:*:*:*:wordpress:*:* | 1.0.1 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.67:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:yottis-simple_portfolio:*:*:*:*:*:wordpress:*:* | 1.0.1 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:helion-agency_\&portfolio:*:*:*:*:*:wordpress:*:* | 1.0.3 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:amuli:*:*:*:*:*:wordpress:*:* | 1.0.2 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:nelson-barbershop_\+_tattoo_salon:*:*:*:*:*:wordpress:*:* | 1.0.1.2001 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* | ||
| cpe:2.3:a:themerex:hallelujah-church:*:*:*:*:*:wordpress:*:* | 1.0.1 (excluding) | |
| cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* |
To consult the complete list of CPE names with products and versions, see this page



