CVE-2026-1969
MEDIUMThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
Title source: cnaDescription
The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448
Scores
CVSS v3
5.3
EPSS
0.0005
EPSS Percentile
15.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-434
Status
published
Products (1)
Unknown/trx_addons
< 2.38.5
Published
Mar 23, 2026
Tracked Since
Mar 23, 2026