CVE-2025-31048: WordPress Shopo <= 1.1.4 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through <= 1.1.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31048?
CVE-2025-31048 is a critical vulnerability that allows unrestricted file uploads, potentially leading to a web shell upload on the server.
How do I fix CVE-2025-31048?
To fix CVE-2025-31048, update Themify Shopo to version 1.1.5 or later, which addresses this vulnerability.
What software versions are affected by CVE-2025-31048?
CVE-2025-31048 affects Themify Shopo and WordPress Shopo versions up to and including 1.1.4.
What are the potential consequences of CVE-2025-31048?
Exploiting CVE-2025-31048 can allow attackers to upload malicious files, potentially compromising the web server.
Is CVE-2025-31048 actively being exploited?
While there are no specific reports of active exploitation for CVE-2025-31048, its nature makes it a high-risk vulnerability.