CVE-2024-13448: ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trxaddonsuploadssavedata' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13448?
CVE-2024-13448 is considered a high-severity vulnerability due to its potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2024-13448?
To fix CVE-2024-13448, update the ThemeREX Addons plugin to version 2.34.0 or later.
Who is affected by CVE-2024-13448?
CVE-2024-13448 affects all versions of the ThemeREX Addons plugin for WordPress up to and including version 2.32.3.
Can CVE-2024-13448 be exploited without authentication?
Yes, CVE-2024-13448 can be exploited by unauthenticated users due to a lack of file type validation.
What kind of attacks can CVE-2024-13448 enable?
CVE-2024-13448 enables attackers to upload arbitrary files, which could lead to further exploitation of the web server.