CVE-2025-0682
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 25, 2025
CWE ID 98
Summary
CVE-2025-0682 is a vulnerability affecting the ThemeREX Addons plugin for WordPress. Versions up to 2.33.0 are impacted, allowing authenticated attackers with contributor-level permissions and above to execute arbitrary files on the server through the 'trx_sc_reviews' shortcode 'type' attribute. This Local File Inclusion vulnerability can be exploited to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.