Sceawere
Vulnerability Detail
CVE-2026-102797UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ThemeREX Addons SSRF Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 10h ago
- Vendor
- ThemeREX Group
- Product
- ThemeREX Addons
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-02T13:17:22.730Z",
"pubdate": "2026-10-02T13:17:22.730Z",
"executiveSummary": "The ThemeREX Addons plugin, a component frequently utilized within ThemeREX WordPress themes, contains a Server-Side Request Forgery (SSRF) vulnerability.\nThis vulnerability originates from improper handling of user-supplied input, allowing unauthorized parties to induce the server into performing requests to arbitrary destinations.\nThe flaw affects versions from n/a through 2.46.0 of the ThemeREX Addons plugin.\nBy exploiting this SSRF, an unauthenticated or authenticated attacker could potentially bypass firewall restrictions, access internal network resources, or perform port scanning against the local infrastructure hosting the WordPress instance.\nThe impact is significant, as it effectively leverages the server as a proxy to interact with private services that are not reachable from the public internet, potentially leading to the disclosure of sensitive internal data or unauthorized interaction with internal management interfaces.\nThe vulnerability is inherent to the plugin's code logic and persists until updated, posing a risk to the integrity and confidentiality of the internal network architecture.",
"technicalDetails": "The vulnerability is a Server-Side Request Forgery (SSRF) found within the ThemeREX Addons plugin, specifically affecting all versions up to and including 2.46.0.\nThe root cause of this vulnerability lies in the plugin's failure to adequately validate and sanitize user-supplied input before using it to initiate server-side HTTP requests.\nIn a typical SSRF attack flow, an attacker identifies a parameter or input field within the plugin's functionality that accepts a URL or host address.\nBecause the application does not implement a whitelist of allowed domains or protocols, or perform proper address validation, an attacker can manipulate this input to point to internal IP addresses (e.g., 127.0.0.1 or 192.168.x.x) or sensitive local services.\nWhen the plugin processes this malicious input, the server-side code executes a request to the target specified by the attacker, effectively masquerading the request as coming from the trusted web server environment.\nThis behavior allows the attacker to bypass perimeter security measures such as network access control lists (ACLs) or firewalls, which typically permit traffic originating from the web server itself to internal network segments.\nThe exploitation method involves crafting a request containing a malicious URL, which is then submitted to the vulnerable endpoint within the ThemeREX Addons plugin.\nUpon processing, the plugin initiates an outgoing connection from the server. The response from the internal resource, or the ability to confirm connectivity based on timing or error messages, allows the attacker to map the internal network structure or interact with services.\nPost-exploitation impact includes the ability to interact with cloud metadata services (e.g., http://169.254.169.254/ to steal instance credentials), gain access to unauthenticated administration panels on local network devices, or conduct reconnaissance on private network segments that were previously shielded from direct external access.\nThe vulnerability does not explicitly specify authentication requirements in the initial disclosure; however, such flaws are often reachable without elevated privileges depending on the specific endpoint exposed by the plugin."
}