Themify Event Post

Themify Event Post has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include PHP Remote File Inclusion.

Every one of the 4 issues recorded for Themify Event Post has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, most of them (2) reported by LVT-tholv2k. Themify Event Post is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Themify Event Post vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2025-30831

Themify Event Post <= 1.3.2 - Authenticated (Contributor+) Local File Inclusion

Read the full analysis

Vulnerability Records

4 records
Plugin Profile
Latestv1.3.7

Themify Event Post

themifyme

Author

themifyme

5.0(2)
100/100
Last Updated
2026-08-05 (1mo ago)
Active Installs
3,000+
Downloads
92,594
Requires WP
5.2+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2018-08-20 (8y ago)

Have an upcoming event or an interesting sale you’d like to share on your WordPress website? The Themify Event Post Type plugin allows users to create an event specific post type. Here’s what it can do: Event Details Area: you can input the day, start & end time, and location Map Input Field: you can input an address to display a Google Map Buy Button Link: you can enter a link to a ticket buying page Repeat Option: you can opt to automatically replicate the event weekly or even daily When used with the Themify Builder plugin it’ll also come with its own Event Post module.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C