CVE-2025-5394

CRITICAL EXPLOITED NUCLEI

Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE

Title source: llm

Description

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.

Exploits (5)

nomisec WORKING POC 3 stars
by fokda-prodz · remote
https://github.com/fokda-prodz/CVE-2025-5394
nomisec WORKING POC 3 stars
by Nxploited · remote
https://github.com/Nxploited/CVE-2025-5394
nomisec WORKING POC 1 stars
by Yucaerin · remote
https://github.com/Yucaerin/CVE-2025-5394
nomisec WORKING POC
by qalesyaSN · remote
https://github.com/qalesyaSN/CVE-2025-5394
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-5394

Nuclei Templates (1)

Unauthenticated Arbitrary Plugin Upload in Alone Theme
CRITICALVERIFIEDby Nxploited,DhiyaneshDK
FOFA: body="/wp-content/themes/alone/"

Scores

CVSS v3 9.8
EPSS 0.2800
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2025-07-29

Classification

CWE
CWE-862
Status draft

Timeline

Published Jul 15, 2025
Tracked Since Feb 18, 2026