Attackers actively exploit critical zero-day in Alone WordPress Theme
ID: e35cf882-9a24-5c9f-a10f-7b38e4416aae
STIX ID: report--e35cf882-9a24-5c9f-a10f-7b38e4416aae
Feed Name: Security Affairs
Attackers are actively exploiting a critical zero-day (CVE-2025-5394, CVSS 9.8) in the Alone WordPress theme that allows unauthenticated arbitrary file upload via the alone_import_pack_install_plugin() endpoint, enabling remote code execution and full site takeover; exploitation began before public disclosure, thousands of exploit attempts were blocked (over 120,900), and observed payloads include ZIP archives with PHP backdoors—site owners should update the theme, audit admin accounts, and search logs for requests to /wp-admin/admin-ajax.php?action=alone_import_pack_install_plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
