VendorsThemeREXaddonsall versions
Vulnerabilities

ThemeREX Addons

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-10257
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Published 2020-03-09 · Modified
9.8EPSS 0.089
CVE-2024-13448
ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data
Published 2025-01-28 · Analyzed
9.8EPSS 0.009
CVE-2025-0682
ThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode
Published 2025-01-25 · Analyzed
8.8EPSS 0.006
CVE-2025-6997
ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function
Published 2025-07-19 · Analyzed
6.4EPSS 0.002