Summary of Vulnerability CVE-2024-13448: ThemeREX Addons Plugin Remote File Upload Vulnerability
The recent identification of a high-severity Local File Inclusion (LFI) vulnerability in the ThemeREX Addons plugin for WordPress has raised alarm in the web development community. This vulnerability, designated as CVE-2025-0682, allows authenticated attackers with contributor-level and above permissions to execute arbitrary files on the server. Published on January 25, 2025, this weakness affects all…
