The ThemeREX Addons plugin for WordPress has a security flaw that affects various versions. This security flaw allows anyone to execute certain functions with the /trx_addons/v2/get/sc_layout REST API endpoint. This means unauthenticated attackers can inject administrative accounts and take control of websites. For accurate version information