Server-Side Request Forgery Vulnerability in ThemeREX Addons by ThemeREX Group
CVE-2026-102797
6.4MEDIUM
What is CVE-2026-102797?
A vulnerability exists in ThemeREX Addons provided by ThemeREX Group, where improper validation of requests may allow an attacker to perform Server-Side Request Forgery (SSRF). This can result in unauthorized access to internal resources and sensitive data. The vulnerability is found in versions from n/a to 2.46.0, highlighting the importance of securing websites utilizing this plugin against potential exploitations.
Affected Version(s)
ThemeREX Addons 0 <= 2.46.0