SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10257

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls…

CRITICAL 9.8EPSS 8.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
8.88% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-94, CWE-862
Affected
themerex/addons · themerex/ozeum-museum · themerex/chit club-board games · themerex/yottis-simple portfolio · themerex/helion-agency \&portfolio · themerex/amuli · themerex/nelson-barbershop \+ tattoo salon · themerex/hallelujah-church · themerex/right way · themerex/prider-pride fest · themerex/mystik-esoterics · themerex/skydiving and flying company · themerex/dronex-aerial photography services · themerex/samadhi-buddhist · themerex/tantum-rent a car\, rent a bike\, rent a scooter multiskin theme · themerex/scientia-public library · themerex/blabber · themerex/impacto patronus multi-landing · themerex/rare radio · themerex/piqes-creative startup \& agency wordpress theme · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.