trx_addons WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability exists in the trx_addons WordPress plugin in versions prior to 2.38.5, where the plugin fails to properly validate file types in one of its AJAX actions. This flaw allows unauthenticated users to upload arbitrary files. The issue arises from an incorrect resolution of a previous vulnerability, CVE-2024-13448.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, which may be used to execute malicious code or disrupt site functionality.

Remediation

Users are advised to update the trx_addons WordPress plugin to version 2.38.5 or later.

Added: Mar 23, 2026, 6:25 AM
Updated: Mar 23, 2026, 6:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.