Themerex
Themerex Addons: vulnerabilidades y CVE
Themerex Addons tiene 8 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses4
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97236 | Media (6.5) | 0.22% | — | 30 sept 2026 | Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| CVE-2026-97235 | Alta (7.1) | 0.25% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| CVE-2026-62105 | Crítica (9.8) | 0.56% | — | 11 sept 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. |
| CVE-2025-60205 | Crítica (9.8) | 0.53% | — | 17 jun 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. |
| CVE-2025-6997 | Media (5.4) | 0.21% | — | 19 jul 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and output escaping. The… |
| CVE-2024-13448 | Crítica (9.8) | 0.89% | — | 28 ene 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This… |
| CVE-2025-0682 | Alta (8.8) | 0.62% | — | 25 ene 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' shortcode 'type' attribute. This makes it possible for authenticated… |
| CVE-2020-10257 | Crítica (9.8) | 8.9% | — | 10 mar 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.