CVE-2026-1969: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1969 is an unauthenticated arbitrary file upload vulnerability in the ThemeREX Addons (trx_addons) WordPress plugin affecting versions before 2.38.5. The flaw stems from an incorrect fix of a prior vulnerability, CVE-2024-13448, where file type validation in an AJAX action remains insufficient. It was publicly disclosed on March 2, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (WPScan, Feedly).

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and exists in the plugin's AJAX action handler trx_addons_ai_helper_agenerator. The endpoint accepts multipart form-data file uploads but fails to properly validate the file type of the upload_voice parameter, allowing PHP or other dangerous files to be uploaded despite the prior patch attempt for CVE-2024-13448. Exploitation requires a nonce (retrievable from the site homepage via TRX_ADDONS_STORAGE.ajax_nonce) and either an OpenAI or ModelsLab API token to be configured on the target site, as well as a compatible theme using the plugin (WPScan).

Impact

Successful exploitation allows an unauthenticated attacker to upload arbitrary files — including PHP web shells — to the target WordPress server. This can lead to remote code execution, full site compromise, data theft, defacement, or use of the server as a pivot point for further attacks. The CVSS integrity impact is rated Low due to the preconditions required (API token configuration), but the practical risk of RCE upon successful upload is significant (WPScan, Feedly).

Exploitability

A public proof-of-concept (PoC) has been published by WPScan researcher Erwan LR, demonstrating the exploit via a crafted multipart HTTP POST request. The EPSS score is approximately 0.023% (0.000230), indicating low but non-zero automated exploitation probability at this time. No CISA KEV catalog listing or confirmed in-the-wild exploitation has been reported as of the disclosure date (WPScan, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the ThemeREX Addons (trx_addons) plugin version below 2.38.5 with a compatible theme active. Confirm that the site has OpenAI or ModelsLab API tokens configured (required precondition).
  2. Retrieve nonce: Visit the target site's homepage and extract the AJAX nonce from the JavaScript variable TRX_ADDONS_STORAGE.ajax_nonce in the page source.
  3. Craft malicious request: Prepare a multipart/form-data HTTP POST request to /wp-admin/admin-ajax.php?action=trx_addons_ai_helper_agenerator with the retrieved nonce, including a PHP web shell as the upload_voice file parameter (e.g., filename shell.php, Content-Type text/php) and a benign file as upload_audio.
  4. Upload web shell: Submit the crafted request. The insufficient file type validation allows the PHP file to be saved to the server's upload directory.
  5. Achieve RCE: Access the uploaded PHP shell via its URL on the target server to execute arbitrary commands (WPScan).

Indicators of compromise

  • Network: Unusual multipart/form-data POST requests to /wp-admin/admin-ajax.php?action=trx_addons_ai_helper_agenerator from unauthenticated (non-logged-in) sources; outbound connections from the web server to unknown external IPs following such requests.
  • File System: Unexpected PHP files (e.g., .php extensions) appearing in WordPress upload directories (/wp-content/uploads/) or plugin directories; files with names inconsistent with media uploads.
  • Logs: Web server access logs showing POST requests to the above AJAX endpoint with multipart/form-data content type and upload_voice parameters containing non-audio file types; HTTP 200 responses to these requests from unauthenticated sessions.
  • Process: Unusual child processes spawned by the web server process (e.g., php, bash, curl, wget) following suspicious upload activity (WPScan).

Mitigation and workarounds

Update the ThemeREX Addons (trx_addons) WordPress plugin to version 2.38.5 or later, which contains the corrected file type validation fix. No official workaround short of upgrading has been published; as an interim measure, administrators can disable the plugin or restrict access to the wp-admin/admin-ajax.php endpoint for unauthenticated users via WAF rules. Removing or revoking OpenAI/ModelsLab API tokens from the plugin settings also eliminates the precondition required for exploitation (WPScan).

Community reactions

The vulnerability was discovered and reported by Erwan LR of WPScan, who also published the proof-of-concept. Coverage has appeared on threat intelligence aggregators and security feeds including Infinit Security, Radar Offseq, and CVEFeed, reflecting standard community attention for a WordPress plugin file upload flaw. No major vendor statements or notable researcher debate beyond the WPScan disclosure have been identified (WPScan, Infinit Security).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management