
🚨 CVE-2024-13448: ThemeREX Addons <= 2.32.3 - Unau... Zero validation on file uploads = instant webshells for script kiddies; 9.8 CVSS with unauthenticated RCE makes this a ... https://zerodaysignal.com/vulnerability/CVE-2024-13448 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces a high‑severity (9.8 CVSS) unauthenticated remote code execution flaw in ThemeREX Addons <= 2.32.3 due to unvalidated file uploads, enabling instant webshells, with no evidence of active exploitation, patch, or PoC provided.
