PT-2026-1513 · Themify · Themify Folo+8

Published

2026-01-06

·

Updated

2026-01-07

·

CVE-2025-30996

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themify Sidepane WordPress Theme versions n/a through 1.9.8 Themify Newsy versions n/a through 1.9.9 Themify Folo versions n/a through 1.9.6 Themify Edmin versions n/a through 2.0.0 Themify Bloggie versions n/a through 2.0.8 Themify Photobox versions n/a through 2.0.1 Themify Wigi versions n/a through 2.0.1 Themify Rezo versions n/a through 1.9.7 Themify Slide versions n/a through 1.7.5
Description The affected software contains an unrestricted file upload issue. This allows for the upload of dangerous file types, such as web shells, potentially granting attackers full server access. The issue stems from a lack of validation of uploaded files, including file types, extensions, and filtering. Exploitation does not require authentication. Reports indicate that attackers have successfully uploaded malicious files, gaining control of numerous sites utilizing the vulnerable themes. The vulnerability provides a pivot point for mass web shell deployment.
Recommendations Themify Sidepane WordPress Theme versions prior to 1.9.8 should be updated. Themify Newsy versions prior to 1.9.9 should be updated. Themify Folo versions prior to 1.9.6 should be updated. Themify Edmin versions prior to 2.0.0 should be updated. Themify Bloggie versions prior to 2.0.8 should be updated. Themify Photobox versions prior to 2.0.1 should be updated. Themify Wigi versions prior to 2.0.1 should be updated. Themify Rezo versions prior to 1.9.7 should be updated. Themify Slide versions prior to 1.7.5 should be updated.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-30996

Affected Products

Themify Bloggie
Themify Edmin
Themify Folo
Themify Newsy
Themify Photobox
Themify Rezo
Themify Sidepane
Themify Slide
Themify Wigi