9.8

CVE-2020-10257

Exploit

ThemeREX Addons (Various Versions) - Missing Authorization

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Mögliche Gegenmaßnahme
ThemeREX Addons: Update to one of the following versions, or a newer patched version: 1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt ThemeREX Addons
Version [*, 1.6.49.6)
Version [1.6.49.6.2, 1.6.49.6.3)
Version [1.6.49.8, 1.6.49.9)
Version [1.6.50, 1.6.50.2)
Version [1.6.51, 1.6.51.4)
Version [1.6.52, 1.6.52.3)
Version [1.6.53, 1.6.53.4)
Version [1.6.54, 1.6.54.1)
Version [1.6.55, 1.6.55.8)
Version [1.6.56, 1.6.56.1)
Version [1.6.57, 1.6.57.4)
Version [1.6.58.2, 1.6.58.3)
Version 1.6.59
Version 1.6.59.1
Version [1.6.59.1.1, 1.6.59.1.2)
Version [1.6.59.2, 1.6.59.4)
Version [1.6.60, 1.6.60.1)
Version 1.6.61
Version 1.6.61.1
Version [1.6.61.1.0, 1.6.61.1.1)
Version [1.6.61.2, 1.6.61.2.1)
Version [1.6.65, 1.6.65.1)
Version [1.6.66, 1.6.66.1)
Version [1.6.67, 1.6.67.1)
Version 1.70.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ThemerexAddons Version1.70.3 SwPlatformwordpress
ThemerexOzeum-museum SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.70.3 SwPlatformwordpress
ThemerexChit Club-board Games SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.67 SwPlatformwordpress
ThemerexYottis-simple Portfolio SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.66 SwPlatformwordpress
ThemerexHelion-agency &portfolio SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.66 SwPlatformwordpress
ThemerexAmuli SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.65 SwPlatformwordpress
ThemerexNelson-barbershop + Tattoo Salon SwPlatformwordpress Version < 1.0.1.2001
ThemerexAddons Version1.6.65 SwPlatformwordpress
ThemerexHallelujah-church SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.65 SwPlatformwordpress
ThemerexRight Way SwPlatformwordpress Version < 4.0.1
ThemerexAddons Version1.6.65 SwPlatformwordpress
ThemerexPrider-pride Fest SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.62.3 SwPlatformwordpress
ThemerexMystik-esoterics SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.62.3 SwPlatformwordpress
ThemerexSkydiving And Flying Company SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.62.1 SwPlatformwordpress
ThemerexDronex-aerial Photography Services SwPlatformwordpress Version < 1.1.2001
ThemerexAddons Version1.6.61.2 SwPlatformwordpress
ThemerexSamadhi-buddhist SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.61.3 SwPlatformwordpress
ThemerexAddons Version1.6.61.2 SwPlatformwordpress
ThemerexScientia-public Library SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.61.2 SwPlatformwordpress
ThemerexBlabber SwPlatformwordpress Version < 1.5.2009
ThemerexAddons Version1.6.61.1 SwPlatformwordpress
ThemerexImpacto Patronus Multi-landing SwPlatformwordpress Version < 1.1.2001
ThemerexAddons Version1.6.61 SwPlatformwordpress
ThemerexRare Radio SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.60 SwPlatformwordpress
ThemerexPiqes-creative Startup & Agency Wordpress Theme SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.59.3 SwPlatformwordpress
ThemerexKratz-digital Agency SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.59.2 SwPlatformwordpress
ThemerexPixefy SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.59.1.1 SwPlatformwordpress
ThemerexNetmix-broadband & Telecom SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.59 SwPlatformwordpress
ThemerexKids Care SwPlatformwordpress Version < 3.0.5
ThemerexAddons Version1.6.58.2 SwPlatformwordpress
ThemerexBriny-diving Wordpress Theme SwPlatformwordpress Version < 1.2.2000
ThemerexAddons Version1.6.57.3 SwPlatformwordpress
ThemerexTornados SwPlatformwordpress Version < 1.1.2001
ThemerexAddons Version1.6.57.4 SwPlatformwordpress
ThemerexGridiron SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.57.2 SwPlatformwordpress
ThemerexYungen-digital/marketing Agency SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.57.3 SwPlatformwordpress
ThemerexFc United-football SwPlatformwordpress Version < 1.0.7
ThemerexAddons Version1.6.57.2 SwPlatformwordpress
ThemerexBugster-pests Control SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.57 SwPlatformwordpress
ThemerexRumble-single Fighter Boxer, News, Gym, Store SwPlatformwordpress Version < 1.0.4
ThemerexAddons Version1.6.56 SwPlatformwordpress
ThemerexTacticool-shooting Range Wordpress Theme SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.55.4 SwPlatformwordpress
ThemerexAddons Version1.6.55.7 SwPlatformwordpress
ThemerexVihara-ashram, Buddhist SwPlatformwordpress Version < 1.1.2001
ThemerexAddons Version1.6.55.3 SwPlatformwordpress
ThemerexKatelyn-gutenberg Wordpress Blog Theme SwPlatformwordpress Version < 1.0.4
ThemerexAddons Version1.6.55.1 SwPlatformwordpress
ThemerexHeaven 11-multiskin Property Theme SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.54 SwPlatformwordpress
ThemerexEspecio-food Gutenberg Theme SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.53.1 SwPlatformwordpress
ThemerexPartiso Electioncampaign SwPlatformwordpress Version < 1.1.2002
ThemerexAddons Version1.6.53.3 SwPlatformwordpress
ThemerexKargo-freight Transport SwPlatformwordpress Version < 1.1.2004
ThemerexAddons Version1.6.53.2 SwPlatformwordpress
ThemerexMaxify-startup Blog SwPlatformwordpress Version < 1.0.4
ThemerexAddons Version1.6.53.1 SwPlatformwordpress
ThemerexLingvico-language Learning School SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.53.2 SwPlatformwordpress
ThemerexAldo-gutenberg Wordpress Blog Theme SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.52.2 SwPlatformwordpress
ThemerexVixus-startup / Mobile Application SwPlatformwordpress Version < 1.0.4
ThemerexAddons Version1.6.52.1 SwPlatformwordpress
ThemerexWellspring Water Filter Systems SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.52.1 SwPlatformwordpress
ThemerexNazareth-church SwPlatformwordpress Version < 1.0.5
ThemerexAddons Version1.6.53 SwPlatformwordpress
ThemerexTediss-soft Play Area, Cafe & Child Care Center SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.51.3 SwPlatformwordpress
ThemerexYolox-startup Magazine & Blog Wordpress Theme SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.51.3 SwPlatformwordpress
ThemerexMeals And Wheels-food Truck SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.51.1 SwPlatformwordpress
ThemerexRosalinda-vegetarian & Health Coach SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.50 SwPlatformwordpress
ThemerexVapester SwPlatformwordpress Version < 1.1.2001
ThemerexAddons Version1.6.50 SwPlatformwordpress
ThemerexModern Housewife-housewife And Family Blog SwPlatformwordpress Version < 1.0.2
ThemerexAddons Version1.6.50.1 SwPlatformwordpress
ThemerexChainpress SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.51.1 SwPlatformwordpress
ThemerexJustitia-multiskin Lawyer Theme SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.50 SwPlatformwordpress
ThemerexHobo Digital Nomad Blog SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.50.1 SwPlatformwordpress
ThemerexRhodos-creative Corporate Wordpress Theme SwPlatformwordpress Version < 1.3.2001
ThemerexAddons Version1.6.50 SwPlatformwordpress
ThemerexBuzz Stone-magazine & Blog SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.0.49.10 SwPlatformwordpress
ThemerexCorredo Sport Event SwPlatformwordpress Version < 1.1.2003
ThemerexAddons Version1.6.49.8 SwPlatformwordpress
ThemerexSavejulia Personal Fundraising Campaign SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.49.6 SwPlatformwordpress
ThemerexBonkozoo Zoo SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.49.6.2 SwPlatformwordpress
ThemerexRenewal-plastic Surgeon Clinic SwPlatformwordpress Version < 1.0.3
ThemerexAddons Version1.6.49.5 SwPlatformwordpress
ThemerexGloss Blog SwPlatformwordpress Version < 1.0.1
ThemerexAddons Version1.6.58.2 SwPlatformwordpress
ThemerexAddons Version1.6.61.2 SwPlatformwordpress
ThemerexTopper Theme And Skins Version- SwPlatformwordpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 47.78% 0.976
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
cve@mitre.org 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.