CVE-2025-30996
Last modified
CVE-2025-30996 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7; Slide: from n/a through 1.7.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30996?
How severe is CVE-2025-30996?
How do I fix CVE-2025-30996?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30990Missing Authorization vulnerability in ThemeHunk ThemeHunk t…5.4
- CVE-2025-30991Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-30992Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2025-30993Missing Authorization vulnerability in VillaTheme Thank You …6.5
- CVE-2025-30994Cross-Site Request Forgery (CSRF) vulnerability in Imran Tau…4.3
- CVE-2025-30995Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes…7.1
- CVE-2025-30997Server-Side Request Forgery (SSRF) vulnerability in SmartDat…5.4
- CVE-2025-30998Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2025-30999Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-3100The WP Project Manager – Task, team, and project management …5.4
- CVE-2025-31000Missing Authorization vulnerability in Miguel Fuentes Paymen…5.3
- CVE-2025-31001Debug Messages Revealing Unnecessary Information vulnerabili…7.5
Are you affected by CVE-2025-30996?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
