PT-2026-1265 · WordPress · Themify Shopo

CVE-2025-31048

·

Published

2026-01-05

·

Updated

2026-01-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themify Shopo versions through 1.1.4
Description The software is susceptible to an unrestricted file upload issue, allowing the upload of files with dangerous types, such as web shells, to a web server. Successful exploitation could lead to remote code execution. The vulnerability requires low-privilege authentication.
Recommendations Versions prior to 1.1.4 should be updated.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-31048

Affected Products

Themify Shopo