Critical severity9.8NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2020-10257
CVE-2020-10257
Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Affected products
2- WordPress/ThemeREX Addonsdescription
- Range: <2020-03-09
Patches
Vulnerability mechanics
References
1- www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addons-now-patched/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.