Themify Shopo Unrestricted File Upload Vulnerability Allowing Web Shell Upload

Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Themify Shopo WordPress theme, specifically in versions through 1.1.4. This vulnerability allows users to upload a web shell to the web server, potentially leading to unauthorized access or control over the server.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which can be used to upload malicious files such as web shells. Once uploaded, these web shells can be executed on the server, leading to a compromise of the web server environment.

Added: Jan 5, 2026, 11:24 AM
Updated: Jan 5, 2026, 11:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.