Local File Inclusion Vulnerability in ThemeREX Addons Plugin for WordPress
CVE-2025-0682
What is CVE-2025-0682?
The ThemeREX Addons plugin for WordPress suffers from a Local File Inclusion vulnerability that impacts all versions up to and including 2.33.0. This issue arises through the 'trx_sc_reviews' shortcode where the 'type' attribute can be manipulated by authenticated attackers with contributor-level permissions or higher. This manipulation allows attackers to include and execute arbitrary files on the web server, potentially leading to unauthorized access, exposure of sensitive information, and execution of arbitrary PHP code. As a result, effective access controls can be bypassed, posing significant risks to the integrity and security of affected WordPress installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ThemeREX Addons * <= 2.33.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved