CVE-2025-30996 PUBLISHED

Arbitrary File Upload Vulnerability in WordPress themes by Themify

Assigner: Patchstack
Reserved: 26.03.2025 Published: 06.01.2026 Updated: 06.01.2026

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Themify
Product Themify Sidepane WordPress Theme
Versions Default: unaffected
  • affected from n/a to 1.9.8 (incl.)
Vendor Themify
Product Themify Newsy
Versions Default: unaffected
  • affected from n/a to 1.9.9 (incl.)
Vendor Themify
Product Themify Folo
Versions Default: unaffected
  • affected from n/a to 1.9.6 (incl.)
Vendor Themify
Product Themify Edmin
Versions Default: unaffected
  • affected from n/a to 2.0.0 (incl.)
Vendor Themify
Product Bloggie
Versions Default: unaffected
  • affected from n/a to 2.0.8 (incl.)
Vendor Themify
Product Photobox
Versions Default: unaffected
  • affected from n/a to 2.0.1 (incl.)
Vendor Themify
Product Wigi
Versions Default: unaffected
  • affected from n/a to 2.0.1 (incl.)
Vendor Themify
Product Rezo
Versions Default: unaffected
  • affected from n/a to 1.9.7 (incl.)
Vendor Themify
Product Slide
Versions Default: unaffected
  • affected from n/a to 1.7.5 (incl.)

Credits

  • Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server