← Back to browse · API

CVE-2020-10257

Severity
CRITICAL
CVSS
9.8
EPSS
0.08877
Risk score
42.31
CISA KEV
No
PoC
No
Published
2020-03-09
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-2712, GHSA-X679-H3R8-6399
Products
n/a:n/a n/a
Sources
euvd EUVD-2020-2712

Description

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

References