Extension WordPress
Vulnérabilités ThemeREX Addons
Cette page rassemble les failles publiées pour ThemeREX Addons, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ThemeREX Addons
5 fiches
ThemeREX Addons < 2.38.5 – Unauthenticated Arbitrary File Upload
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 2.38.5 (exclusive). This makes it possible for unauthenticated attackers to upload arbitrary files on the…
[*, 2.38.5)
2.38.5
30/03/2026
ThemeREX Addons <= 2.35.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function
The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and output escaping. The plugin’s SVG rendering routine calls…
*-2.35.1.1
2.35.2.2
18/07/2025
ThemeREX Addons <= 2.32.3 – Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to…
*-2.32.3
2.34.0
27/01/2025
ThemeREX Addons <= 2.33.0 – Authenticated (Contributor+) Local File Inclusion via Shortcode
The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions,…
*-2.33.0
2.34.0
24/01/2025
ThemeREX Addons (Various Versions) – Missing Authorization
The ThemeREX Addons plugin for WordPress is vulnerable to Improper Access Control in various versions. This is due to the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout…
[*, 1.6.49.6), [1.6.49.6.2, 1.6.49.6.3), [1.6.49.8, 1.6.49.9), [1.6.50, 1.6.50.2), [1.6.51, 1.6.51.4), [1.6.52, 1.6.52.3), [1.6.53, 1.6.53.4), [1.6.54, 1.6.54.1), [1.6.55, 1.6.55.8), [1.6.56, 1.6.56.1), [1.6.57, 1.6.57.4), [1.6.58.2, 1.6.58.3), [1.6.59.1.1, 1.6.59.1.2), [1.6.59.2, 1.6.59.4), [1.6.60, 1.6.60.1), [1.6.61.1.0, 1.6.61.1.1), [1.6.61.2, 1.6.61.2.1), [1.6.65, 1.6.65.1), [1.6.66, 1.6.66.1), [1.6.67, 1.6.67.1), 1.6.59, 1.6.59.1, 1.6.61, 1.6.61.1, 1.70.3
1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1
09/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.