E20-0k761
CVSS:
9.0 (AV:N/AC:L/Au:N/C:P/I:P/A:C)
False Positive:
t
Variants:
4
Year:
2020
Description
A remote code execution vulnerability exists in ThemeRex Addons WordPress Plugin versions greater than 1.6.50, due to lack of sanitization for user-supplied data. By sending a crafed REST-API request to '/wp-json/trx_addons/v2/get/sc_layout', a remote unauthenticated user may invoke arbitrary PHP functions via 'sc' parameter.