
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1969 is an unauthenticated arbitrary file upload vulnerability in the ThemeREX Addons (trx_addons) WordPress plugin affecting versions before 2.38.5. The flaw stems from an incorrect fix of a prior vulnerability, CVE-2024-13448, where file type validation in an AJAX action remains insufficient. It was publicly disclosed on March 2, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (WPScan, Feedly).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and exists in the plugin's AJAX action handler trx_addons_ai_helper_agenerator. The endpoint accepts multipart form-data file uploads but fails to properly validate the file type of the upload_voice parameter, allowing PHP or other dangerous files to be uploaded despite the prior patch attempt for CVE-2024-13448. Exploitation requires a nonce (retrievable from the site homepage via TRX_ADDONS_STORAGE.ajax_nonce) and either an OpenAI or ModelsLab API token to be configured on the target site, as well as a compatible theme using the plugin (WPScan).
Successful exploitation allows an unauthenticated attacker to upload arbitrary files — including PHP web shells — to the target WordPress server. This can lead to remote code execution, full site compromise, data theft, defacement, or use of the server as a pivot point for further attacks. The CVSS integrity impact is rated Low due to the preconditions required (API token configuration), but the practical risk of RCE upon successful upload is significant (WPScan, Feedly).
A public proof-of-concept (PoC) has been published by WPScan researcher Erwan LR, demonstrating the exploit via a crafted multipart HTTP POST request. The EPSS score is approximately 0.023% (0.000230), indicating low but non-zero automated exploitation probability at this time. No CISA KEV catalog listing or confirmed in-the-wild exploitation has been reported as of the disclosure date (WPScan, Feedly).
TRX_ADDONS_STORAGE.ajax_nonce in the page source./wp-admin/admin-ajax.php?action=trx_addons_ai_helper_agenerator with the retrieved nonce, including a PHP web shell as the upload_voice file parameter (e.g., filename shell.php, Content-Type text/php) and a benign file as upload_audio./wp-admin/admin-ajax.php?action=trx_addons_ai_helper_agenerator from unauthenticated (non-logged-in) sources; outbound connections from the web server to unknown external IPs following such requests..php extensions) appearing in WordPress upload directories (/wp-content/uploads/) or plugin directories; files with names inconsistent with media uploads.multipart/form-data content type and upload_voice parameters containing non-audio file types; HTTP 200 responses to these requests from unauthenticated sessions.php, bash, curl, wget) following suspicious upload activity (WPScan).Update the ThemeREX Addons (trx_addons) WordPress plugin to version 2.38.5 or later, which contains the corrected file type validation fix. No official workaround short of upgrading has been published; as an interim measure, administrators can disable the plugin or restrict access to the wp-admin/admin-ajax.php endpoint for unauthenticated users via WAF rules. Removing or revoking OpenAI/ModelsLab API tokens from the plugin settings also eliminates the precondition required for exploitation (WPScan).
The vulnerability was discovered and reported by Erwan LR of WPScan, who also published the proof-of-concept. Coverage has appeared on threat intelligence aggregators and security feeds including Infinit Security, Radar Offseq, and CVEFeed, reflecting standard community attention for a WordPress plugin file upload flaw. No major vendor statements or notable researcher debate beyond the WPScan disclosure have been identified (WPScan, Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."