İçeriğe atla
Noroxi

ThemeREX kayıtları

themerex üreticisine ait 7 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

7 kayıt
  • CVE-2020-10257
    42Planlayın

    The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allow

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    themerex · addons9 Mar 2020

  • CVE-2024-13448
    39İzleyin

    ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data

    KritikCVSS 9,8İstismar yokEPSS %1

    themerex · addons28 Oca 2025

  • CVE-2024-13770
    39İzleyin

    Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    themerex · puzzles13 Şub 2025

  • CVE-2025-0682
    35İzleyin

    ThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode

    YüksekCVSS 8,8İstismar yokEPSS %1

    themerex · addons25 Oca 2025

  • CVE-2024-13769
    21İzleyin

    Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

    OrtaCVSS 5,4İstismar yokEPSS %0

    themerex · puzzles12 Şub 2025

  • CVE-2025-0837
    21İzleyin

    Puzzles <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %0

    themerex · puzzles13 Şub 2025

  • CVE-2025-6997
    21İzleyin

    ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function

    OrtaCVSS 5,4İstismar yokEPSS %0

    themerex · addons19 Tem 2025