WordPress ThemeREX Addons代码注入漏洞
CVE编号
CVE-2020-10257利用情况
暂无补丁情况
N/A披露时间
2020-03-10漏洞描述
WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。ThemeREX Addons是使用在其中的一个网站主题插件。 WordPress ThemeREX Addons 2020-03-09之前版本中存在安全漏洞,该漏洞源于/trx_addons/v2/get/sc_layout REST API端点缺少访问控制。攻击者可利用该漏洞执行PHP函数。解决建议
厂商已发布了漏洞修复程序,请及时关注更新:https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-addons-now-patched/
参考链接 |
|
---|---|
https://www.wordfence.com/blog/2020/03/zero-day-vulnerability-in-themerex-add... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.0.49.10 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.49.5 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.49.6 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.49.6.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.49.8 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.50 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.50.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.51.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.51.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.52.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.52.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.53 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.53.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.53.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.53.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.54 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.55.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.55.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.55.4 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.55.7 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.56 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.57 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.57.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.57.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.57.4 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.58.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.59 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.59.1.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.59.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.59.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.60 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.61 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.61.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.61.2 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.61.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.62.1 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.62.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.65 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.66 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.6.67 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | addons | 1.70.3 | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | aldo-gutenberg_wordpress_blog_theme | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | amuli | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | blabber | * | Up to (excluding) 1.5.2009 | |||||
运行在以下环境 | |||||||||
应用 | themerex | bonkozoo_zoo | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | briny-diving_wordpress_theme | * | Up to (excluding) 1.2.2000 | |||||
运行在以下环境 | |||||||||
应用 | themerex | bugster-pests_control | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | buzz_stone-magazine_&_blog | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | chainpress | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | chit_club-board_games | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | coinpress-cryptocurrency_magazine_&_blog_wordpress_theme | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | corredo_sport_event | * | Up to (excluding) 1.1.2003 | |||||
运行在以下环境 | |||||||||
应用 | themerex | dronex-aerial_photography_services | * | Up to (excluding) 1.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | especio-food_gutenberg_theme | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | fc_united-football | * | Up to (excluding) 1.0.7 | |||||
运行在以下环境 | |||||||||
应用 | themerex | gloss_blog | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | gridiron | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | hallelujah-church | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | heaven_11-multiskin_property_theme | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | helion-agency_&portfolio | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | hobo_digital_nomad_blog | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | impacto_patronus_multi-landing | * | Up to (excluding) 1.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | justitia-multiskin_lawyer_theme | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | kargo-freight_transport | * | Up to (excluding) 1.1.2004 | |||||
运行在以下环境 | |||||||||
应用 | themerex | katelyn-gutenberg_wordpress_blog_theme | * | Up to (excluding) 1.0.4 | |||||
运行在以下环境 | |||||||||
应用 | themerex | kids_care | * | Up to (excluding) 3.0.5 | |||||
运行在以下环境 | |||||||||
应用 | themerex | kratz-digital_agency | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | lingvico-language_learning_school | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | maxify-startup_blog | * | Up to (excluding) 1.0.4 | |||||
运行在以下环境 | |||||||||
应用 | themerex | meals_and_wheels-food_truck | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | modern_housewife-housewife_and_family_blog | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | mystik-esoterics | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | nazareth-church | * | Up to (excluding) 1.0.5 | |||||
运行在以下环境 | |||||||||
应用 | themerex | nelson-barbershop_+_tattoo_salon | * | Up to (excluding) 1.0.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | netmix-broadband_&_telecom | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | ozeum-museum | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | partiso_electioncampaign | * | Up to (excluding) 1.1.2002 | |||||
运行在以下环境 | |||||||||
应用 | themerex | piqes-creative_startup_&_agency_wordpress_theme | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | pixefy | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | plumbing-repair,_building_&_construction_wordpress_theme | * | Up to (excluding) 3.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | prider-pride_fest | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | rare_radio | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | renewal-plastic_surgeon_clinic | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | rhodos-creative_corporate_wordpress_theme | * | Up to (excluding) 1.3.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | right_way | * | Up to (excluding) 4.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | rosalinda-vegetarian_&_health_coach | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | rumble-single_fighter_boxer,_news,_gym,_store | * | Up to (excluding) 1.0.4 | |||||
运行在以下环境 | |||||||||
应用 | themerex | samadhi-buddhist | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | savejulia_personal_fundraising_campaign | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | scientia-public_library | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | skydiving_and_flying_company | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | tacticool-shooting_range_wordpress_theme | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | tantum-rent_a_car,_rent_a_bike,_rent_a_scooter_multiskin_theme | * | Up to (excluding) 1.0.2 | |||||
运行在以下环境 | |||||||||
应用 | themerex | tediss-soft_play_area,_cafe_&_child_care_center | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | topper_theme_and_skins | - | - | |||||
运行在以下环境 | |||||||||
应用 | themerex | tornados | * | Up to (excluding) 1.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | vapester | * | Up to (excluding) 1.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | vihara-ashram,_buddhist | * | Up to (excluding) 1.1.2001 | |||||
运行在以下环境 | |||||||||
应用 | themerex | vixus-startup_/_mobile_application | * | Up to (excluding) 1.0.4 | |||||
运行在以下环境 | |||||||||
应用 | themerex | wellspring_water_filter_systems | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | yolox-startup_magazine_&_blog_wordpress_theme | * | Up to (excluding) 1.0.3 | |||||
运行在以下环境 | |||||||||
应用 | themerex | yottis-simple_portfolio | * | Up to (excluding) 1.0.1 | |||||
运行在以下环境 | |||||||||
应用 | themerex | yungen-digital/marketing_agency | * | Up to (excluding) 1.0.1 |
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 无
- 可用性 高
- 保密性 高
- 完整性 高
CWE-ID | 漏洞类型 |
CWE-862 | 授权机制缺失 |
CWE-94 | 对生成代码的控制不恰当(代码注入) |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论