Sceawere
Vulnerability Detail
CVE-2026-102798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ThemeREX Addons Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- ThemeREX Group
- Product
- ThemeREX Addons
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T13:17:22.883Z",
"pubdate": "2026-10-02T13:17:22.883Z",
"executiveSummary": "The ThemeREX Addons plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability allows unauthenticated or authenticated attackers to inject malicious scripts into the application, which are subsequently stored in the database.\nThese scripts execute in the context of the victim's browser when they visit the affected page, potentially leading to unauthorized actions, session hijacking, or credential theft.\nThe vulnerability affects ThemeREX Addons versions from n/a through 2.46.0.\nThe risk is significant as it permits the persistence of malicious payloads, enabling long-term compromise of user sessions or administrative accounts, depending on who views the affected content.",
"technicalDetails": "The vulnerability exists within the ThemeREX Addons plugin because it fails to adequately sanitize or encode user-provided input before rendering it on web pages. This failure constitutes an improper neutralization of input during web page generation, classified under CWE-79.\nThe attack flow begins when an attacker identifies an input vector within the ThemeREX Addons plugin that is not subjected to strict server-side validation or output escaping. The attacker submits a specially crafted payload—typically JavaScript code embedded within HTML tags—through the vulnerable input field. The application accepts this input and persists it directly into the WordPress database.\nWhen a user or administrator subsequently navigates to a web page where the plugin renders this stored, malicious data, the browser interprets the input as executable script rather than plain text. Because the script originates from the same domain, it executes within the victim's session, bypassing Same-Origin Policy (SOP) protections.\nThe execution of this injected JavaScript can lead to severe post-exploitation impacts. These include, but are not limited to, the theft of sensitive session cookies, enabling account takeover; redirection of users to malicious third-party websites; the modification of page content to conduct phishing attacks; or the execution of unauthorized actions within the WordPress dashboard if the victim is an administrator. Because the payload is stored, the attack is persistent, meaning every user who views the affected component will execute the malicious script.\nThe scope of this vulnerability covers versions from n/a through 2.46.0. The exploit does not necessarily require advanced authentication if the vulnerable input vector is publicly exposed, allowing even unauthenticated attackers to perform the injection. The vulnerability exists at the application layer, specifically within the plugin's data processing logic."
}