CVE-2020-10257
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.88% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94, CWE-862
- Affected
- themerex/addons · themerex/ozeum-museum · themerex/chit club-board games · themerex/yottis-simple portfolio · themerex/helion-agency \&portfolio · themerex/amuli · themerex/nelson-barbershop \+ tattoo salon · themerex/hallelujah-church · themerex/right way · themerex/prider-pride fest · themerex/mystik-esoterics · themerex/skydiving and flying company · themerex/dronex-aerial photography services · themerex/samadhi-buddhist · themerex/tantum-rent a car\, rent a bike\, rent a scooter multiskin theme · themerex/scientia-public library · themerex/blabber · themerex/impacto patronus multi-landing · themerex/rare radio · themerex/piqes-creative startup \& agency wordpress theme · +40 more
- Source
- cve@mitre.org
References
- https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addons-now-patched/Exploit, Third Party Advisory
- https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addons-now-patched/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.