Arbitrary File Upload Vulnerability in Alone Charity Theme for WordPress
CVE-2025-5394

9.8CRITICAL

What is CVE-2025-5394?

The Alone – Charity Multipurpose Non-profit WordPress Theme is affected by a significant security flaw that allows unauthenticated attackers to exploit a lack of capability checks in the alone_import_pack_install_plugin() function. This vulnerability enables attackers to upload malicious ZIP files containing webshells disguised as plugins, potentially leading to remote code execution. All versions up to and including 7.8.3 are susceptible, highlighting the critical need for users to apply security patches promptly to mitigate the risks associated with this dangerous vulnerability.

Affected Version(s)

Alone – Charity Multipurpose Non-profit WordPress Theme * <= 7.8.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thái An
.
CVE-2025-5394 : Arbitrary File Upload Vulnerability in Alone Charity Theme for WordPress