WordPress Plugin Vulnerabilities
ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
Description
The plugin does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-03-02 (about 21 days ago)
Added
2026-03-02 (about 20 days ago)
Last Updated
2026-03-02 (about 20 days ago)