Skip to main content

Vendor archive

themerex CVEs

Beta · best-effort

7 CVEs tagged to vendor themerex2 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-6997

Published Jul 19, 2025

The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0837

Published Feb 13, 2025

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization and outp…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-13770

Published Feb 13, 2025

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deser…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13769

Published Feb 12, 2025

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'them…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13448

Published Jan 28, 2025

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-0682

Published Jan 25, 2025

The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' shortcode 'type' attribute. Th…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1