Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Published: 2020-03-09
Score: 9.8 Critical
EPSS: 66.6% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-2712 The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
History

No history.

Subscriptions

Themerex Addons Aldo-gutenberg Wordpress Blog Theme Amuli Blabber Bonkozoo Zoo Briny-diving Wordpress Theme Bugster-pests Control Buzz Stone-magazine \& Blog Chainpress Chit Club-board Games Coinpress-cryptocurrency Magazine \& Blog Wordpress Theme Corredo Sport Event Dronex-aerial Photography Services Especio-food Gutenberg Theme Fc United-football Gloss Blog Gridiron Hallelujah-church Heaven 11-multiskin Property Theme Helion-agency \&portfolio Hobo Digital Nomad Blog Impacto Patronus Multi-landing Justitia-multiskin Lawyer Theme Kargo-freight Transport Katelyn-gutenberg Wordpress Blog Theme Kids Care Kratz-digital Agency Lingvico-language Learning School Maxify-startup Blog Meals And Wheels-food Truck Modern Housewife-housewife And Family Blog Mystik-esoterics Nazareth-church Nelson-barbershop \+ Tattoo Salon Netmix-broadband \& Telecom Ozeum-museum Partiso Electioncampaign Piqes-creative Startup \& Agency Wordpress Theme Pixefy Plumbing-repair\, Building \& Construction Wordpress Theme Prider-pride Fest Rare Radio Renewal-plastic Surgeon Clinic Rhodos-creative Corporate Wordpress Theme Right Way Rosalinda-vegetarian \& Health Coach Rumble-single Fighter Boxer\, News\, Gym\, Store Samadhi-buddhist Savejulia Personal Fundraising Campaign Scientia-public Library Skydiving And Flying Company Tacticool-shooting Range Wordpress Theme Tantum-rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme Tediss-soft Play Area\, Cafe \& Child Care Center Topper Theme And Skins Tornados Vapester Vihara-ashram\, Buddhist Vixus-startup \/ Mobile Application Wellspring Water Filter Systems Yolox-startup Magazine \& Blog Wordpress Theme Yottis-simple Portfolio Yungen-digital\/marketing Agency
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:58:40.181Z

Reserved: 2020-03-09T00:00:00.000Z

Link: CVE-2020-10257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-10T00:15:10.757

Modified: 2024-11-21T04:55:05.053

Link: CVE-2020-10257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses