WordPress security by component
ThemeREX Addons
Plugin description
ThemeREX Addons adds widgets, shortcodes, and extensions for ThemeREX WordPress themes.
ThemeREX Addons (trx-addons) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
trx-addonsLatest vulnerability
CVE-2026-62105: ThemeREX Addons permits unauthenticated PHP object injection
ThemeREX Addons before 2.45.0 permits PHP object injection without authentication. The CNA vector requires no privileges or user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the endpoint, parameter, deserialization operation, usable gadget chain, or the exact post-injection effect.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62105
ThemeREX Addons permits unauthenticated PHP object injection
ThemeREX Addons before 2.45.0 permits PHP object injection without authentication. The CNA vector requires no privileges or user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the endpoint, parameter, deserialization operation, usable gadget chain, or the exact post-injection effect.
|
2.45.0 |
CVE9.8
NVDPending
|
| Jun 17, 2026 |
CVE-2025-60205
ThemeREX Addons: Code execution
ThemeREX Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.36.1.1.
|
2.36.2 |
CVE9.8
NVDPending
|
| Mar 23, 2026 |
CVE-2026-1969
trx_addons: A security weakness
trx_addons is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|