nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13448 CVE-2024-13448
CRITICAL
ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data
Record summary
CVE-2024-13448 has a selected CVSS score of 9.8 (critical).
Description
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ThemeREX AddonsBrowse ThemeREX / ThemeREX AddonsDefault status: unaffected | CVE List | Through 2.32.3 | affected |
addonsBrowse themerex / addons | VulnCheck | Version data not supplied | |
References
3themeforest.net
https://themeforest.net/item/qwery-multipurpose-business-wordpress-theme/29678687 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/7c1372bd-821d-439c-9b11-dfa5f08dd0dd?source=cve