CVE-2013-20002: Themify Framework
Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
Affected products
- Themify Framework: before 1.2.2 (fixed in 1.2.2)
Published 2021-06-17. Last modified 2026-06-16.