Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress ThemeREX Addons plugin to the latest available version (at least 2.47.0).
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0. | |
| Title | WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-02T12:39:34.767Z
Reserved: 2026-09-29T17:03:12.949Z
Link: CVE-2026-102797
No data.
Status : Deferred
Published: 2026-10-02T13:17:22.730
Modified: 2026-10-02T13:18:55.613
Link: CVE-2026-102797
No data.
OpenCVE Enrichment
No data.
-
CWE-918
Server-Side Request Forgery (SSRF)