CVE-2025-31013: WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS.
This issue affects Themify Folo: from n/a through 1.9.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wordpress/themify-folofrom your environment.Uninstall or deactivate the Themify Folo WordPress theme (versions <= 1.9.6) if it is not required. Replace it with an updated or alternative theme that is not vulnerable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31013?
CVE-2025-31013 has a severity rating of high, specifically 7.1 on the CVSS scale.
How do I fix CVE-2025-31013?
To fix CVE-2025-31013, you should update the Themify Folo theme to version 1.9.7 or later.
What type of vulnerability is CVE-2025-31013?
CVE-2025-31013 is a Reflected Cross Site Scripting (XSS) vulnerability.
Which versions of Themify Folo are affected by CVE-2025-31013?
CVE-2025-31013 affects Themify Folo versions from n/a up to and including 1.9.6.
What impact does CVE-2025-31013 have on users?
CVE-2025-31013 can allow an attacker to execute malicious scripts in the context of the user’s browser.