CVE-2020-10257

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2020
Last modified:
21/07/2021

Description

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:ozeum-museum:*:*:*:*:*:wordpress:*:* 1.0.2 (excluding)
cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:chit_club-board_games:*:*:*:*:*:wordpress:*:* 1.0.1 (excluding)
cpe:2.3:a:themerex:addons:1.6.67:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:yottis-simple_portfolio:*:*:*:*:*:wordpress:*:* 1.0.1 (excluding)
cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:helion-agency_\&portfolio:*:*:*:*:*:wordpress:*:* 1.0.3 (excluding)
cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:amuli:*:*:*:*:*:wordpress:*:* 1.0.2 (excluding)
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:nelson-barbershop_\+_tattoo_salon:*:*:*:*:*:wordpress:*:* 1.0.1.2001 (excluding)
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:*
cpe:2.3:a:themerex:hallelujah-church:*:*:*:*:*:wordpress:*:* 1.0.1 (excluding)
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:*