Metrics
- CVSS v4.0 N/A
- CVSS v3.1 9.8 Critical
- CVSS v3.0 9.8 Critical
- CVSS v2 7.5 High
- KEV no
- EPSS 0.54229
- SSVC no
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.54229.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Themerex
Subscribe
|
Addons
Subscribe
Aldo-gutenberg Wordpress Blog Theme
Subscribe
Amuli
Subscribe
Blabber
Subscribe
Bonkozoo Zoo
Subscribe
Briny-diving Wordpress Theme
Subscribe
Bugster-pests Control
Subscribe
Buzz Stone-magazine \& Blog
Subscribe
Chainpress
Subscribe
Chit Club-board Games
Subscribe
Coinpress-cryptocurrency Magazine \& Blog Wordpress Theme
Subscribe
Corredo Sport Event
Subscribe
Dronex-aerial Photography Services
Subscribe
Especio-food Gutenberg Theme
Subscribe
Fc United-football
Subscribe
Gloss Blog
Subscribe
Gridiron
Subscribe
Hallelujah-church
Subscribe
Heaven 11-multiskin Property Theme
Subscribe
Helion-agency \&portfolio
Subscribe
Hobo Digital Nomad Blog
Subscribe
Impacto Patronus Multi-landing
Subscribe
Justitia-multiskin Lawyer Theme
Subscribe
Kargo-freight Transport
Subscribe
Katelyn-gutenberg Wordpress Blog Theme
Subscribe
Kids Care
Subscribe
Kratz-digital Agency
Subscribe
Lingvico-language Learning School
Subscribe
Maxify-startup Blog
Subscribe
Meals And Wheels-food Truck
Subscribe
Modern Housewife-housewife And Family Blog
Subscribe
Mystik-esoterics
Subscribe
Nazareth-church
Subscribe
Nelson-barbershop \+ Tattoo Salon
Subscribe
Netmix-broadband \& Telecom
Subscribe
Ozeum-museum
Subscribe
Partiso Electioncampaign
Subscribe
Piqes-creative Startup \& Agency Wordpress Theme
Subscribe
Pixefy
Subscribe
Plumbing-repair\, Building \& Construction Wordpress Theme
Subscribe
Prider-pride Fest
Subscribe
Rare Radio
Subscribe
Renewal-plastic Surgeon Clinic
Subscribe
Rhodos-creative Corporate Wordpress Theme
Subscribe
Right Way
Subscribe
Rosalinda-vegetarian \& Health Coach
Subscribe
Rumble-single Fighter Boxer\, News\, Gym\, Store
Subscribe
Samadhi-buddhist
Subscribe
Savejulia Personal Fundraising Campaign
Subscribe
Scientia-public Library
Subscribe
Skydiving And Flying Company
Subscribe
Tacticool-shooting Range Wordpress Theme
Subscribe
Tantum-rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme
Subscribe
Tediss-soft Play Area\, Cafe \& Child Care Center
Subscribe
Topper Theme And Skins
Subscribe
Tornados
Subscribe
Vapester
Subscribe
Vihara-ashram\, Buddhist
Subscribe
Vixus-startup \/ Mobile Application
Subscribe
Wellspring Water Filter Systems
Subscribe
Yolox-startup Magazine \& Blog Wordpress Theme
Subscribe
Yottis-simple Portfolio
Subscribe
Yungen-digital\/marketing Agency
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Configuration 6 [-]
|
Configuration 7 [-]
|
Configuration 8 [-]
|
Configuration 9 [-]
|
Configuration 10 [-]
|
Configuration 11 [-]
|
Configuration 12 [-]
|
Configuration 13 [-]
|
Configuration 14 [-]
|
Configuration 15 [-]
|
Configuration 16 [-]
|
Configuration 17 [-]
|
Configuration 18 [-]
|
Configuration 19 [-]
|
Configuration 20 [-]
|
Configuration 21 [-]
|
Configuration 22 [-]
|
Configuration 23 [-]
|
Configuration 24 [-]
|
Configuration 25 [-]
|
Configuration 26 [-]
|
Configuration 27 [-]
|
Configuration 28 [-]
|
Configuration 29 [-]
|
Configuration 30 [-]
|
Configuration 31 [-]
|
Configuration 32 [-]
|
Configuration 33 [-]
|
Configuration 34 [-]
|
Configuration 35 [-]
|
Configuration 36 [-]
|
Configuration 37 [-]
|
Configuration 38 [-]
|
Configuration 39 [-]
|
Configuration 40 [-]
|
Configuration 41 [-]
|
Configuration 42 [-]
|
Configuration 43 [-]
|
Configuration 44 [-]
|
Configuration 45 [-]
|
Configuration 46 [-]
|
Configuration 47 [-]
|
Configuration 48 [-]
|
Configuration 49 [-]
|
Configuration 50 [-]
|
Configuration 51 [-]
|
Configuration 52 [-]
|
Configuration 53 [-]
|
Configuration 54 [-]
|
Configuration 55 [-]
|
Configuration 56 [-]
|
Configuration 57 [-]
|
Configuration 58 [-]
|
Configuration 59 [-]
|
Configuration 60 [-]
|
Configuration 61 [-]
|
Configuration 62 [-]
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2712 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:58:40.181Z
Reserved: 2020-03-09T00:00:00
Link: CVE-2020-10257
No data.
Status : Modified
Published: 2020-03-10T00:15:10.757
Modified: 2024-11-21T04:55:05.053
Link: CVE-2020-10257
No data.
OpenCVE Enrichment
No data.
EUVD