← back
CVE-2020-10257criticalobserved exploitation

CVE-2020-10257

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 8.9%
from disclosure to weapon
Published on NVDMar 9
VulnCheckMar 9
exploitation probability
8.9%top 5% of all CVEs
observed exploitation
yesVulnCheck
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Affected products
n/a · n/a