PT-2026-1265 · WordPress · Themify Shopo

Published

2026-01-05

·

Updated

2026-01-10

·

CVE-2025-31048

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themify Shopo versions through 1.1.4
Description The software is susceptible to an unrestricted file upload issue, allowing the upload of files with dangerous types, such as web shells, to a web server. Successful exploitation could lead to remote code execution. The vulnerability requires low-privilege authentication.
Recommendations Versions prior to 1.1.4 should be updated.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-31048

Affected Products

Themify Shopo