CVE-2025-30831
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-30831 is a filename vulnerability affecting Themify Event Post, a PHP program. The issue enables local file inclusion, allowing unauthorized access to sensitive data. The Themify Event Post, from version n/a through 1.3.2, is vulnerable to this PHP Remote File Inclusion (RFI) vulnerability. Successful exploitation of this vulnerability could lead to significant security risks, including data theft, system compromise, or unauthorized access to restricted functionality. Users are advised to update their Themify Event Post instances to a secure version as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress