N/A
2026-03-30< 2.38.5
ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
Minimum safe version
2.38.5
Update to 2.38.5 or later to address 5 fixable vulnerabilities
ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function
CVE-2024-13448
WordPress ThemeREX Addons Plugin <= 2.33.0 is vulnerable to Local File Inclusion
CVE-2020-10257