Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical vulnerability in the ThemeREX Addons WordPress plugin (CVE-2026-1969) allows any unauthenticated attacker to upload malicious files directly to affected web servers, bypassing all login requirements. Organizations running WordPress sites with the trx_addons plugin prior to version 2.38.5 face immediate risk of full server compromise, including data theft and ransomware deployment. CISA KEV and VulnCheck KEV both list this vulnerability with confirmed active exploitation, meaning attacks are occurring now, not hypothetically.

Author

Tech Jacks Solutions