Arbitrary File Upload Vulnerability in ThemeREX Addons Plugin for WordPress
CVE-2024-13448
What is CVE-2024-13448?
The ThemeREX Addons plugin for WordPress has a security flaw that allows for arbitrary file uploads due to insufficient file type validation in the 'trx_addons_uploads_save_data' function. This vulnerability affects all versions up to and including 2.32.3 and opens the door for unauthenticated attackers to potentially upload malicious files to the server of an affected site. Such an exploit can lead to serious security breaches, including remote code execution, putting user data and website integrity at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ThemeREX Addons * <= 2.32.3
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved