CVE-2025-5394
CRITICAL EXPLOITED NUCLEIAlone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
Title source: llmDescription
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
Exploits (5)
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-5394
Nuclei Templates (1)
Unauthenticated Arbitrary Plugin Upload in Alone Theme
CRITICALVERIFIEDby Nxploited,DhiyaneshDK
FOFA:
body="/wp-content/themes/alone/"
Scores
CVSS v3
9.8
EPSS
0.2800
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2025-07-29
Classification
CWE
CWE-862
Status
draft
Timeline
Published
Jul 15, 2025
Tracked Since
Feb 18, 2026