Arbitrary File Upload Vulnerability in Alone Charity Theme for WordPress
CVE-2025-5394
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 July 2025
What is CVE-2025-5394?
The Alone – Charity Multipurpose Non-profit WordPress Theme is affected by a significant security flaw that allows unauthenticated attackers to exploit a lack of capability checks in the alone_import_pack_install_plugin() function. This vulnerability enables attackers to upload malicious ZIP files containing webshells disguised as plugins, potentially leading to remote code execution. All versions up to and including 7.8.3 are susceptible, highlighting the critical need for users to apply security patches promptly to mitigate the risks associated with this dangerous vulnerability.
Affected Version(s)
Alone – Charity Multipurpose Non-profit WordPress Theme * <= 7.8.3