The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Themerex
Subscribe
|
Addons
Subscribe
Aldo-gutenberg Wordpress Blog Theme
Subscribe
Amuli
Subscribe
Blabber
Subscribe
Bonkozoo Zoo
Subscribe
Briny-diving Wordpress Theme
Subscribe
Bugster-pests Control
Subscribe
Buzz Stone-magazine \& Blog
Subscribe
Chainpress
Subscribe
Chit Club-board Games
Subscribe
Coinpress-cryptocurrency Magazine \& Blog Wordpress Theme
Subscribe
Corredo Sport Event
Subscribe
Dronex-aerial Photography Services
Subscribe
Especio-food Gutenberg Theme
Subscribe
Fc United-football
Subscribe
Gloss Blog
Subscribe
Gridiron
Subscribe
Hallelujah-church
Subscribe
Heaven 11-multiskin Property Theme
Subscribe
Helion-agency \&portfolio
Subscribe
Hobo Digital Nomad Blog
Subscribe
Impacto Patronus Multi-landing
Subscribe
Justitia-multiskin Lawyer Theme
Subscribe
Kargo-freight Transport
Subscribe
Katelyn-gutenberg Wordpress Blog Theme
Subscribe
Kids Care
Subscribe
Kratz-digital Agency
Subscribe
Lingvico-language Learning School
Subscribe
Maxify-startup Blog
Subscribe
Meals And Wheels-food Truck
Subscribe
Modern Housewife-housewife And Family Blog
Subscribe
Mystik-esoterics
Subscribe
Nazareth-church
Subscribe
Nelson-barbershop \+ Tattoo Salon
Subscribe
Netmix-broadband \& Telecom
Subscribe
Ozeum-museum
Subscribe
Partiso Electioncampaign
Subscribe
Piqes-creative Startup \& Agency Wordpress Theme
Subscribe
Pixefy
Subscribe
Plumbing-repair\, Building \& Construction Wordpress Theme
Subscribe
Prider-pride Fest
Subscribe
Rare Radio
Subscribe
Renewal-plastic Surgeon Clinic
Subscribe
Rhodos-creative Corporate Wordpress Theme
Subscribe
Right Way
Subscribe
Rosalinda-vegetarian \& Health Coach
Subscribe
Rumble-single Fighter Boxer\, News\, Gym\, Store
Subscribe
Samadhi-buddhist
Subscribe
Savejulia Personal Fundraising Campaign
Subscribe
Scientia-public Library
Subscribe
Skydiving And Flying Company
Subscribe
Tacticool-shooting Range Wordpress Theme
Subscribe
Tantum-rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme
Subscribe
Tediss-soft Play Area\, Cafe \& Child Care Center
Subscribe
Topper Theme And Skins
Subscribe
Tornados
Subscribe
Vapester
Subscribe
Vihara-ashram\, Buddhist
Subscribe
Vixus-startup \/ Mobile Application
Subscribe
Wellspring Water Filter Systems
Subscribe
Yolox-startup Magazine \& Blog Wordpress Theme
Subscribe
Yottis-simple Portfolio
Subscribe
Yungen-digital\/marketing Agency
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2712 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:58:40.181Z
Reserved: 2020-03-09T00:00:00
Link: CVE-2020-10257
No data.
Status : Modified
Published: 2020-03-10T00:15:10.757
Modified: 2024-11-21T04:55:05.053
Link: CVE-2020-10257
No data.
OpenCVE Enrichment
No data.
EUVD