Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0.
Published: 2026-10-02
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) in the plugin
Action: Immediate Patch
AI Analysis

Impact

This issue arises from improper neutralization of user input in the ThemeREX Addons addon, allowing attackers to store malicious JavaScript within the plugin’s static content or form fields. The vulnerability permits a stored XSS attack, which can execute arbitrary scripts in the browsers of users who view the affected content, potentially leading to credential theft, session hijacking, or defacement of the website. The weakness is a classic CWE-79, and the impact is confined to users who can view the compromised pages, not to the server itself or data confidentiality. The CVSS score of 6.5 reflects a medium‑to‑high severity for web applications where client‑side code injection can compromise user sessions.

Affected Systems

The affected product is the WordPress ThemeREX Addons plugin delivered by ThemeREX Group. All releases from the earliest available version up through 2.46.0 are vulnerable. The vulnerability would affect any WordPress site that has this plugin installed and is using any of those versions, regardless of site configuration or theme.

Risk and Exploitability

The vulnerability carries a CVSS of 6.5 and is not listed in CISA’s KEV catalog. No EPSS score is available, so the current exploitation probability is unknown but potentially modest. Attackers would likely exploit the plug‑in’s form or content storage mechanisms using a browser with sufficient privileges; the stored payload would persist in the database and execute every time affected content is rendered. Because the impact is limited to the victim’s browser session, credential hijacking or site defacement are realistic possible outcomes. In the absence of a patch, the risk remains medium‑to‑high for any site that has active users who browse dynamically rendered content from the plugin.

Generated by OpenCVE AI on October 2, 2026 at 13:25 UTC.

Remediation

Vendor Solution

Update the WordPress ThemeREX Addons plugin to the latest available version (at least 2.47.0).


OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading WordPress ThemeREX Addons to version 2.47.0 or later.
  • Remove or sanitize any malicious script content that may already be stored in the plugin’s database entries before upgrading.
  • If an upgrade cannot be performed immediately, disable the vulnerable plugin or restrict access to administrative functions that allow content submission to mitigate the risk until a patch is applied.

Generated by OpenCVE AI on October 2, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0.
Title WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-02T13:29:59.525Z

Reserved: 2026-09-29T17:03:13.655Z

Link: CVE-2026-102798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T13:17:22.883

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-102798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')