CVE-2020-10257

CVSS V2 High 7.5 CVSS V3 Critical 9.8
Description
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Overview
  • CVE ID
  • CVE-2020-10257
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-03-10T00:15:10
  • Last Modified Date
  • 2021-07-21T11:39:23
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:ozeum-museum:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.70.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:chit_club-board_games:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.67:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:yottis-simple_portfolio:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:helion-agency_\&portfolio:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.66:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:amuli:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:nelson-barbershop_\+_tattoo_salon:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1.2001
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:hallelujah-church:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:right_way:*:*:*:*:*:wordpress:*:* 1 AND 4.0.1
cpe:2.3:a:themerex:addons:1.6.65:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:prider-pride_fest:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.62.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:mystik-esoterics:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.62.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:skydiving_and_flying_company:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.62.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:dronex-aerial_photography_services:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2001
cpe:2.3:a:themerex:addons:1.6.61.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:samadhi-buddhist:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.61.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:tantum-rent_a_car\,_rent_a_bike\,_rent_a_scooter_multiskin_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.61.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:scientia-public_library:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.61.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:blabber:*:*:*:*:*:wordpress:*:* 1 AND 1.5.2009
cpe:2.3:a:themerex:addons:1.6.61.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:impacto_patronus_multi-landing:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2001
cpe:2.3:a:themerex:addons:1.6.61:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:rare_radio:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.60:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:piqes-creative_startup_\&_agency_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.59.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:kratz-digital_agency:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.59.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:pixefy:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.59.1.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:netmix-broadband_\&_telecom:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.59:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:kids_care:*:*:*:*:*:wordpress:*:* 1 AND 3.0.5
cpe:2.3:a:themerex:addons:1.6.58.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:briny-diving_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.2.2000
cpe:2.3:a:themerex:addons:1.6.57.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:tornados:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2001
cpe:2.3:a:themerex:addons:1.6.57.4:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:gridiron:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.57.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:yungen-digital\/marketing_agency:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.57.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:fc_united-football:*:*:*:*:*:wordpress:*:* 1 AND 1.0.7
cpe:2.3:a:themerex:addons:1.6.57.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:bugster-pests_control:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.57:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:rumble-single_fighter_boxer\,_news\,_gym\,_store:*:*:*:*:*:wordpress:*:* 1 AND 1.0.4
cpe:2.3:a:themerex:addons:1.6.56:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:tacticool-shooting_range_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.55.4:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:coinpress-cryptocurrency_magazine_\&_blog_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.55.7:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:vihara-ashram\,_buddhist:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2001
cpe:2.3:a:themerex:addons:1.6.55.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:katelyn-gutenberg_wordpress_blog_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.4
cpe:2.3:a:themerex:addons:1.6.55.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:heaven_11-multiskin_property_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.54:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:especio-food_gutenberg_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.53.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:partiso_electioncampaign:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2002
cpe:2.3:a:themerex:addons:1.6.53.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:kargo-freight_transport:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2004
cpe:2.3:a:themerex:addons:1.6.53.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:maxify-startup_blog:*:*:*:*:*:wordpress:*:* 1 AND 1.0.4
cpe:2.3:a:themerex:addons:1.6.53.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:lingvico-language_learning_school:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.53.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:aldo-gutenberg_wordpress_blog_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.52.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:vixus-startup_\/_mobile_application:*:*:*:*:*:wordpress:*:* 1 AND 1.0.4
cpe:2.3:a:themerex:addons:1.6.52.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:wellspring_water_filter_systems:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.52.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:nazareth-church:*:*:*:*:*:wordpress:*:* 1 AND 1.0.5
cpe:2.3:a:themerex:addons:1.6.53:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:tediss-soft_play_area\,_cafe_\&_child_care_center:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.51.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:yolox-startup_magazine_\&_blog_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.51.3:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:meals_and_wheels-food_truck:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.51.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:rosalinda-vegetarian_\&_health_coach:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.50:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:vapester:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2001
cpe:2.3:a:themerex:addons:1.6.50:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:modern_housewife-housewife_and_family_blog:*:*:*:*:*:wordpress:*:* 1 AND 1.0.2
cpe:2.3:a:themerex:addons:1.6.50.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:chainpress:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.51.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:justitia-multiskin_lawyer_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.50:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:hobo_digital_nomad_blog:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.50.1:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:rhodos-creative_corporate_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 1.3.2001
cpe:2.3:a:themerex:addons:1.6.50:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:buzz_stone-magazine_\&_blog:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.0.49.10:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:corredo_sport_event:*:*:*:*:*:wordpress:*:* 1 AND 1.1.2003
cpe:2.3:a:themerex:addons:1.6.49.8:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:savejulia_personal_fundraising_campaign:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.49.6:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:bonkozoo_zoo:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.49.6.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:renewal-plastic_surgeon_clinic:*:*:*:*:*:wordpress:*:* 1 AND 1.0.3
cpe:2.3:a:themerex:addons:1.6.49.5:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:gloss_blog:*:*:*:*:*:wordpress:*:* 1 AND 1.0.1
cpe:2.3:a:themerex:addons:1.6.58.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:plumbing-repair\,_building_\&_construction_wordpress_theme:*:*:*:*:*:wordpress:*:* 1 AND 3.0.1
cpe:2.3:a:themerex:addons:1.6.61.2:*:*:*:*:wordpress:*:* 1 AND
cpe:2.3:a:themerex:topper_theme_and_skins:-:*:*:*:*:wordpress:*:* 1 AND
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
References
History
Created Old Value New Value Data Type Notes
2022-05-10 07:01:06 Added to TrackCVE
2022-12-04 12:16:34 2020-03-10T00:15Z 2020-03-10T00:15:10 CVE Published Date updated
2022-12-04 12:16:34 2021-07-21T11:39:23 CVE Modified Date updated
2022-12-04 12:16:34 Analyzed Vulnerability Status updated