CVE-2020-10257

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)


Configuration 2 (hide)


Configuration 3 (hide)


Configuration 4 (hide)


Configuration 5 (hide)


Configuration 6 (hide)


Configuration 7 (hide)


Configuration 8 (hide)


Configuration 9 (hide)


Configuration 10 (hide)


Configuration 11 (hide)


Configuration 12 (hide)


Configuration 13 (hide)


Configuration 14 (hide)


Configuration 15 (hide)


Configuration 16 (hide)


Configuration 17 (hide)


Configuration 18 (hide)


Configuration 19 (hide)


Configuration 20 (hide)


Configuration 21 (hide)


Configuration 22 (hide)


Configuration 23 (hide)


Configuration 24 (hide)


Configuration 25 (hide)


Configuration 26 (hide)


Configuration 27 (hide)


Configuration 28 (hide)


Configuration 29 (hide)


Configuration 30 (hide)


Configuration 31 (hide)


Configuration 32 (hide)


Configuration 33 (hide)


Configuration 34 (hide)


Configuration 35 (hide)


Configuration 36 (hide)


Configuration 37 (hide)


Configuration 38 (hide)


Configuration 39 (hide)


Configuration 40 (hide)


Configuration 41 (hide)


Configuration 42 (hide)


Configuration 43 (hide)


Configuration 44 (hide)


Configuration 45 (hide)


Configuration 46 (hide)


Configuration 47 (hide)


Configuration 48 (hide)


Configuration 49 (hide)


Configuration 50 (hide)


Configuration 51 (hide)


Configuration 52 (hide)


Configuration 53 (hide)


Configuration 54 (hide)


Configuration 55 (hide)


Configuration 56 (hide)


Configuration 57 (hide)


Configuration 58 (hide)


Configuration 59 (hide)


Configuration 60 (hide)


Configuration 61 (hide)


Configuration 62 (hide)


Information

Published : 2020-03-09 17:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-10257

Mitre link : CVE-2020-10257


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

themerex

  • chit_club-board_games
  • plumbing-repair\,_building_\&_construction_wordpress_theme
  • maxify-startup_blog
  • tediss-soft_play_area\,_cafe_\&_child_care_center
  • heaven_11-multiskin_property_theme
  • partiso_electioncampaign
  • rare_radio
  • yottis-simple_portfolio
  • corredo_sport_event
  • meals_and_wheels-food_truck
  • dronex-aerial_photography_services
  • renewal-plastic_surgeon_clinic
  • helion-agency_\&portfolio
  • aldo-gutenberg_wordpress_blog_theme
  • impacto_patronus_multi-landing
  • vihara-ashram\,_buddhist
  • blabber
  • pixefy
  • justitia-multiskin_lawyer_theme
  • kids_care
  • vixus-startup_\/_mobile_application
  • buzz_stone-magazine_\&_blog
  • bonkozoo_zoo
  • savejulia_personal_fundraising_campaign
  • coinpress-cryptocurrency_magazine_\&_blog_wordpress_theme
  • yolox-startup_magazine_\&_blog_wordpress_theme
  • gloss_blog
  • especio-food_gutenberg_theme
  • skydiving_and_flying_company
  • nelson-barbershop_\+_tattoo_salon
  • yungen-digital\/marketing_agency
  • rumble-single_fighter_boxer\,_news\,_gym\,_store
  • hobo_digital_nomad_blog
  • mystik-esoterics
  • prider-pride_fest
  • piqes-creative_startup_\&_agency_wordpress_theme
  • gridiron
  • nazareth-church
  • kargo-freight_transport
  • kratz-digital_agency
  • rosalinda-vegetarian_\&_health_coach
  • hallelujah-church
  • katelyn-gutenberg_wordpress_blog_theme
  • lingvico-language_learning_school
  • vapester
  • right_way
  • fc_united-football
  • tornados
  • tantum-rent_a_car\,_rent_a_bike\,_rent_a_scooter_multiskin_theme
  • modern_housewife-housewife_and_family_blog
  • amuli
  • bugster-pests_control
  • tacticool-shooting_range_wordpress_theme
  • briny-diving_wordpress_theme
  • chainpress
  • rhodos-creative_corporate_wordpress_theme
  • ozeum-museum
  • topper_theme_and_skins
  • addons
  • wellspring_water_filter_systems
  • samadhi-buddhist
  • netmix-broadband_\&_telecom
  • scientia-public_library