CVE-2025-0682

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 25, 2025
CWE ID 98

Summary

CVE-2025-0682 is a vulnerability affecting the ThemeREX Addons plugin for WordPress. Versions up to 2.33.0 are impacted, allowing authenticated attackers with contributor-level permissions and above to execute arbitrary files on the server through the 'trx_sc_reviews' shortcode 'type' attribute. This Local File Inclusion vulnerability can be exploited to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share