Arbitrary File Upload Vulnerability in WordPress themes by Themify
Summary
| CVE | CVE-2025-30996 |
|---|---|
| State | PUBLISHED |
| Assigner | Patchstack |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-01-06 21:15:42 UTC |
| Updated | 2026-04-28 19:30:52 UTC |
| Description | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5. |
Risk And Classification
Primary CVSS: v3.1 9.9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.000630000 probability, percentile 0.195410000 (date 2026-04-28)
Problem Types: CWE-434 | CWE-434 CWE-434 Unrestricted Upload of File with Dangerous Type
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Themify | Themify Sidepane WordPress Theme | affected n/a 1.9.8 custom | Not specified |
| CNA | Themify | Themify Newsy | affected n/a 1.9.9 custom | Not specified |
| CNA | Themify | Themify Folo | affected n/a 1.9.6 custom | Not specified |
| CNA | Themify | Themify Edmin | affected n/a 2.0.0 custom | Not specified |
| CNA | Themify | Bloggie | affected n/a 2.0.8 custom | Not specified |
| CNA | Themify | Photobox | affected n/a 2.0.1 custom | Not specified |
| CNA | Themify | Wigi | affected n/a 2.0.1 custom | Not specified |
| CNA | Themify | Rezo | affected n/a 1.9.7 custom | Not specified |
| CNA | Themify | Slide | affected n/a 1.7.5 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| patchstack.com/database/wordpress/theme/sidepane/vulnerability/wordpress-the... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/folo/vulnerability/wordpress-themify... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/rezo/vulnerability/wordpress-rezo-1-... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/newsy/vulnerability/wordpress-themif... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/bloggie/vulnerability/wordpress-blog... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/wigi/vulnerability/wordpress-wigi-2-... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/slide/vulnerability/wordpress-slide-... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/edmin/vulnerability/wordpress-themif... | [email protected] | patchstack.com | |
| patchstack.com/database/wordpress/theme/photobox/vulnerability/wordpress-pho... | [email protected] | patchstack.com | |
| https://patchstack.com/database/wordpress/theme/newsy/vulnerability/wordpress-themify-newsy-1-9-9-arbitrary-file-upload-vulnerability?_s_id=cve | MITRE | patchstack.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program (en)
There are currently no legacy QID mappings associated with this CVE.