CVE-2026-1969
MEDIUM EXPLOITEDThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
Title source: cnaExploitation Summary
CVE-2026-1969 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab.
AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-2026-1969, describing an unauthenticated arbitrary file upload vulnerability in the ThemeREX Addons WordPress plugin (versions < 2.38.5). No exploit code or technical details beyond a brief description are provided.
Description
The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448
Exploits (1)
The repository contains a placeholder markdown file for CVE-2026-1969, describing an unauthenticated arbitrary file upload vulnerability in the ThemeREX Addons WordPress plugin (versions < 2.38.5). No exploit code or technical details beyond a brief description are provided.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N