CVE-2025-30964: WordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in EPC Photography. This issue affects Photography: from n/a through 7.5.2.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30964?
CVE-2025-30964 is categorized as a high severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-30964?
To remediate CVE-2025-30964, update the EPC Photography software or WordPress Photography theme to version 7.5.3 or later.
What impact does CVE-2025-30964 have?
CVE-2025-30964 allows attackers to manipulate server requests, potentially leading to unauthorized access to internal resources.
Which versions of EPC Photography are affected by CVE-2025-30964?
CVE-2025-30964 affects all versions of EPC Photography from n/a up to and including 7.5.2.
Is there a known exploit for CVE-2025-30964?
Yes, CVE-2025-30964 has been identified as exploitable, which makes it critical to apply patches or updates immediately.