ThemeREX kayıtları
themerex üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
- CWE-862 Missing Authorization1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2020-10257Kavram kanıtı | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowthemerex · addons · CWE-94 | Kritik9,8 | — | %8,9 | 9 Mar 2020 |
39İzleyin | CVE-2024-13448İstismar yok | ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_datathemerex · addons · CWE-434 | Kritik9,8 | — | %0,9 | 28 Oca 2025 |
39İzleyin | CVE-2024-13770İstismar yok | Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object Injectionthemerex · puzzles · CWE-502 | Kritik9,8 | — | %0,8 | 13 Şub 2025 |
35İzleyin | CVE-2025-0682İstismar yok | ThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via Shortcodethemerex · addons · CWE-98 | Yüksek8,8 | — | %0,6 | 25 Oca 2025 |
21İzleyin | CVE-2024-13769İstismar yok | Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scriptingthemerex · puzzles · CWE-862 | Orta5,4 | — | %0,3 | 12 Şub 2025 |
21İzleyin | CVE-2025-0837İstismar yok | Puzzles <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodethemerex · puzzles · CWE-79 | Orta5,4 | — | %0,3 | 13 Şub 2025 |
21İzleyin | CVE-2025-6997İstismar yok | ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Functionthemerex · addons · CWE-79 | Orta5,4 | — | %0,2 | 19 Tem 2025 |
- CVE-2020-1025742Planlayın
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allow
KritikCVSS 9,8Kavram kanıtıEPSS %9themerex · addons9 Mar 2020
- CVE-2024-1344839İzleyin
ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data
KritikCVSS 9,8İstismar yokEPSS %1themerex · addons28 Oca 2025
- CVE-2024-1377039İzleyin
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %1themerex · puzzles13 Şub 2025
- CVE-2025-068235İzleyin
ThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode
YüksekCVSS 8,8İstismar yokEPSS %1themerex · addons25 Oca 2025
- CVE-2024-1376921İzleyin
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0themerex · puzzles12 Şub 2025
- CVE-2025-083721İzleyin
Puzzles <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0themerex · puzzles13 Şub 2025
- CVE-2025-699721İzleyin
ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function
OrtaCVSS 5,4İstismar yokEPSS %0themerex · addons19 Tem 2025