Hackers Exploit Critical WordPress Theme Flaw to Hijack Sites via Remote Plugin Install
A serious security hole in the "Alone – Charity Multipurpose Non-profit WordPress Theme" is being actively used by threat actors to take control of vulnerable websites.
The vulnerability has a CVSS score of 9.8 and is tagged as CVE-2025-5394. The bug's discovery and reporting are attributed to security researcher Thái An.
Wordfence claims that the flaw is related to an arbitrary file upload that impacts all plugin versions before and including 7.8.3. Version 7.8.5, which was made available on June 16, 2025, addressed it.
Originating from a plugin installation function called "alone_import_pack_install_plugin()" and resulting from a missing capability check, CVE-2025-5394 enables unauthenticated users to execute malware by deploying arbitrary plugins from external sources using AJ...










