← WordPress Vulnerabilities
WordPress security by component

ThemeREX Addons

ThemeREX Addons is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: trx-addons

CVE-2025-60205: ThemeREX Addons: Code execution

ThemeREX Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.36.1.1.

PublishedJun 17, 2026
Known safe version2.36.2
Safe version
Jun 17, 2026 CVE-2025-60205
ThemeREX Addons: Code execution
ThemeREX Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.36.1.1.
2.36.2
CVE9.8
NVDPending
Mar 23, 2026 CVE-2026-1969
trx_addons: A security weakness
trx_addons is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending