WordPress Plugin Vulnerabilities

ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload

Description

The plugin does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

Proof of Concept

Affects Plugins

Fixed in 2.38.5

References

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-03-02 (about 21 days ago)
Added
2026-03-02 (about 20 days ago)
Last Updated
2026-03-02 (about 20 days ago)

Other