VYPR

Trx Addons

by WordPress

CVEs (2)

  • CVE-2026-62105CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

  • CVE-2026-1969MedMar 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448