CVE-2020-10257
WordPress vulnerability analysis and mitigation

Overview

The ThemeREX Addons plugin for WordPress was found to contain a critical security vulnerability (CVE-2020-10257) before the March 9, 2020 update. The vulnerability stemmed from a lack of access control on the /trx_addons/v2/get/sc_layout REST API endpoint, which affected multiple versions of the plugin. This security flaw was discovered and publicly disclosed on February 18, 2020 (WPScan).

Technical details

The vulnerability exists in the includes/plugin.rest-api.php file where the trx_addons_rest_get_sc_layout function processes an unsafe 'sc' parameter through the REST API endpoint. The severity of this vulnerability is rated as Critical with a CVSS score of 9.8. The flaw is classified as an Injection vulnerability (OWASP Top 10 A1) and is categorized under CWE-94 (WPScan).

Impact

This vulnerability allows attackers to remotely execute code on sites with the affected plugin installed. The impact is severe as it enables malicious actors to execute arbitrary PHP functions, including the ability to inject administrative user accounts into the WordPress installation (WPScan).

Mitigation and workarounds

Multiple versions of the plugin have been patched to address this vulnerability, including versions 1.70.3.1, 1.6.61.1.1, 1.6.59.1.2, and several others. Users are strongly advised to update to the latest patched version of the plugin that corresponds to their installation (WPScan, Wordfence Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23550CRITICAL10
  • modular-connector
NoYesJan 14, 2026
CVE-2025-12166HIGH7.5
  • simply-schedule-appointments
NoYesJan 14, 2026
CVE-2026-0813MEDIUM4.4
  • short-link
NoNoJan 14, 2026
CVE-2026-0812MEDIUM4.4
  • linkedin-sc
NoNoJan 14, 2026
CVE-2026-0741MEDIUM4.4
  • electric-studio-download-counter
NoNoJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management