Arbitrary File Upload
2 records40%First: 2025. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 5 vulnerability records associated with ThemeREX Addons, published between 2020 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2020 | 1 | |
| 2025 | 3 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 60% |
| High | 1 | 20% |
| Medium | 1 | 20% |
First: 2025. Latest: 2026.
First: 2020. Latest: 2020.
First: 2025. Latest: 2025.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.38.52.35.2.22.34.01.70.3.11.6.67.11.6.66.11.6.65.11.6.62.41.6.61.2.11.6.61.1.11.6.60.11.6.59.41.6.59.1.21.6.58.31.6.57.41.6.56.11.6.55.81.6.54.11.6.53.41.6.52.31.6.51.41.6.50.21.6.49.71.6.49.6.31.6.49.61.6.49.10Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[1.6.50, 1.6.50.2) | ThemeREX Addons (Various Versions) - Missing Authorization | March 9, 2020 | 1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1 | Critical |
[1.6.49.8, 1.6.49.9) | ThemeREX Addons (Various Versions) - Missing Authorization | March 9, 2020 | 1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1 | Critical |
[1.6.49.6.2, 1.6.49.6.3) | ThemeREX Addons (Various Versions) - Missing Authorization | March 9, 2020 | 1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1 | Critical |
[*, 1.6.49.6) | ThemeREX Addons (Various Versions) - Missing Authorization | March 9, 2020 | 1.6.49.10, 1.6.49.6, 1.6.49.6.3, 1.6.49.7, 1.6.50.2, 1.6.51.4, 1.6.52.3, 1.6.53.4, 1.6.54.1, 1.6.55.8, 1.6.56.1, 1.6.57.4, 1.6.58.3, 1.6.59.1.2, 1.6.59.4, 1.6.60.1, 1.6.61.1.1, 1.6.61.2.1, 1.6.62.4, 1.6.65.1, 1.6.66.1, 1.6.67.1, 1.70.3.1 | Critical |
Selected source records
Published: March 30, 2026
Published: July 18, 2025
Published: January 27, 2025
Published: January 24, 2025
Published: March 9, 2020
Published: March 9, 2020
Published: January 27, 2025
Published: March 30, 2026
Published: January 24, 2025
Published: July 18, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.