trx_addons WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability
Vulnerability
A vulnerability exists in the trx_addons WordPress plugin in versions prior to 2.38.5, where the plugin fails to properly validate file types in one of its AJAX actions. This flaw allows unauthenticated users to upload arbitrary files. The issue arises from an incorrect resolution of a previous vulnerability, CVE-2024-13448.
Impact
Exploitation of this vulnerability could lead to unauthorized file uploads, which may be used to execute malicious code or disrupt site functionality.
Remediation
Users are advised to update the trx_addons WordPress plugin to version 2.38.5 or later.
Added: Mar 23, 2026, 6:25 AM
Updated: Mar 23, 2026, 6:25 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.4remediation
0.0relevance
4.6threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
