Vulnerability Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themerex | Addons | 1.70.3 |
| Themerex | Ozeum-Museum | < 1.0.2 |
| Themerex | Chit Club-Board Games | < 1.0.1 |
| Themerex | Yottis-Simple Portfolio | < 1.0.1 |
| Themerex | Helion-Agency \&Portfolio | < 1.0.3 |
| Themerex | Amuli | < 1.0.2 |
| Themerex | Nelson-Barbershop \+ Tattoo Salon | < 1.0.1.2001 |
| Themerex | Hallelujah-Church | < 1.0.1 |
| Themerex | Right Way | < 4.0.1 |
| Themerex | Prider-Pride Fest | < 1.0.2 |
| Themerex | Mystik-Esoterics | < 1.0.1 |
| Themerex | Skydiving And Flying Company | < 1.0.1 |
| Themerex | Dronex-Aerial Photography Services | < 1.1.2001 |
| Themerex | Samadhi-Buddhist | < 1.0.1 |
| Themerex | Tantum-Rent A Car\, Rent A Bike\, Rent A Scooter Multiskin Theme | < 1.0.2 |
| Themerex | Scientia-Public Library | < 1.0.1 |
| Themerex | Blabber | < 1.5.2009 |
| Themerex | Impacto Patronus Multi-Landing | < 1.1.2001 |
| Themerex | Rare Radio | < 1.0.1 |
| Themerex | Piqes-Creative Startup \& Agency Wordpress Theme | < 1.0.1 |
Related Weaknesses (CWE)
References
- https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addonsExploitThird Party Advisory
- https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addonsExploitThird Party Advisory
FAQ
What is CVE-2020-10257?
CVE-2020-10257 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because i...
How severe is CVE-2020-10257?
CVE-2020-10257 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-10257?
Check the references section above for vendor advisories and patch information. Affected products include: Themerex Addons, Themerex Ozeum-Museum, Themerex Chit Club-Board Games, Themerex Yottis-Simple Portfolio, Themerex Helion-Agency \&Portfolio.