CVE-2020-10257 - CVE House
Back to Database
Status published Critical CVE-2020-10257

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access...

Vulnerability Description

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10257

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

addons, ozeum-museum, chit club-board games, yottis-simple portfolio, helion-agency \&portfolio, amuli, nelson-barbershop \+ tattoo salon, hallelujah-church, right way, prider-pride fest, mystik-esoterics, skydiving and flying company, dronex-aerial photography services, samadhi-buddhist, tantum-rent a car\, rent a bike\, rent a scooter multiskin theme, scientia-public library, blabber, impacto patronus multi-landing, rare radio, piqes-creative startup \& agency wordpress theme, kratz-digital agency, pixefy, netmix-broadband \& telecom, kids care, briny-diving wordpress theme, tornados, gridiron, yungen-digital\/marketing agency, fc united-football, bugster-pests control, rumble-single fighter boxer\, news\, gym\, store, tacticool-shooting range wordpress theme, coinpress-cryptocurrency magazine \& blog wordpress theme, vihara-ashram\, buddhist, katelyn-gutenberg wordpress blog theme, heaven 11-multiskin property theme, especio-food gutenberg theme, partiso electioncampaign, kargo-freight transport, maxify-startup blog, lingvico-language learning school, aldo-gutenberg wordpress blog theme, vixus-startup \/ mobile application, wellspring water filter systems, nazareth-church, tediss-soft play area\, cafe \& child care center, yolox-startup magazine \& blog wordpress theme, meals and wheels-food truck, rosalinda-vegetarian \& health coach, vapester, modern housewife-housewife and family blog, chainpress, justitia-multiskin lawyer theme, hobo digital nomad blog, rhodos-creative corporate wordpress theme, buzz stone-magazine \& blog, corredo sport event, savejulia personal fundraising campaign, bonkozoo zoo, renewal-plastic surgeon clinic, gloss blog, plumbing-repair\, building \& construction wordpress theme, topper theme and skins
Vulnerable Versions:
1.70.3, 1.6.67, 1.6.66, 1.6.65, 1.6.62.3, 1.6.62.1, 1.6.61.2, 1.6.61.3, 1.6.61.1, 1.6.61, 1.6.60, 1.6.59.3, 1.6.59.2, 1.6.59.1.1, 1.6.59, 1.6.58.2, 1.6.57.3, 1.6.57.4, 1.6.57.2, 1.6.57, 1.6.56, 1.6.55.4, 1.6.55.7, 1.6.55.3, 1.6.55.1, 1.6.54, 1.6.53.1, 1.6.53.3, 1.6.53.2, 1.6.52.2, 1.6.52.1, 1.6.53, 1.6.51.3, 1.6.51.1, 1.6.50, 1.6.50.1, 1.0.49.10, 1.6.49.8, 1.6.49.6, 1.6.49.6.2, 1.6.49.5, 0

Timeline

Official Publish: March 9th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.