logo

Attackers actively exploit critical zero-day in Alone WordPress Theme

ID: e35cf882-9a24-5c9f-a10f-7b38e4416aae

STIX ID: report--e35cf882-9a24-5c9f-a10f-7b38e4416aae

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting a critical zero-day (CVE-2025-5394, CVSS 9.8) in the Alone WordPress theme that allows unauthenticated arbitrary file upload via the alone_import_pack_install_plugin() endpoint, enabling remote code execution and full site takeover; exploitation began before public disclosure, thousands of exploit attempts were blocked (over 120,900), and observed payloads include ZIP archives with PHP backdoors—site owners should update the theme, audit admin accounts, and search logs for requests to /wp-admin/admin-ajax.php?action=alone_import_pack_install_plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.