CVE-2026-1969: ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
Published Mar 23, 2026
·Updated
The trxaddons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448
Affected Software
1 affected component
ThemeREX ThemeREX Addons (trx_addons WordPress plugin)<2.38.5
Event History
Mar 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-1969?
CVE-2026-1969 is classified as a high-severity vulnerability due to its potential for arbitrary file upload by unauthenticated users.
2
How do I fix CVE-2026-1969?
To fix CVE-2026-1969, update the ThemeREX Addons plugin to version 2.38.5 or later.
3
What type of vulnerability is CVE-2026-1969?
CVE-2026-1969 is an unauthenticated arbitrary file upload vulnerability.
4
Who is affected by CVE-2026-1969?
Anyone using ThemeREX Addons plugin versions prior to 2.38.5 is affected by CVE-2026-1969.
5
What can attackers do with CVE-2026-1969?
Attackers can upload arbitrary files to the server, potentially leading to further exploitation or unauthorized access.