« Volver al listado

Themerex

Themerex Addons: vulnerabilidades y CVE

Themerex Addons tiene 8 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses4
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97236Media (6.5)0.22%—30 sept 2026
Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
CVE-2026-97235Alta (7.1)0.25%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
CVE-2026-62105Crítica (9.8)0.56%—11 sept 2026
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
CVE-2025-60205Crítica (9.8)0.53%—17 jun 2026
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVE-2025-6997Media (5.4)0.21%—19 jul 2025
The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and output escaping. The…
CVE-2024-13448Crítica (9.8)0.89%—28 ene 2025
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This…
CVE-2025-0682Alta (8.8)0.62%—25 ene 2025
The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' shortcode 'type' attribute. This makes it possible for authenticated…
CVE-2020-10257Crítica (9.8)8.9%—10 mar 2020
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Themerex