Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x679-h3r8-6399

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

EPSS

Процентиль: 98%
0.47784
Средний

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

EPSS

Процентиль: 98%
0.47784
Средний

Дефекты

CWE-94