The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-23 06:16
Updated : 2026-03-23 14:31
NVD link : CVE-2026-1969
Mitre link : CVE-2026-1969
CVE.ORG link : CVE-2026-1969
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
