Warning: A critical vulnerability in the Alone-Charity Multipurpose Non-profit WordPress Theme is currently being actively exploited. Patch Immediately!
ID: 1057a7cb-5c0f-5da9-ab0c-e72bda30f95f
STIX ID: report--1057a7cb-5c0f-5da9-ab0c-e72bda30f95f
CVE-2025-5394 is a critical (CVSS 9.8) arbitrary file upload vulnerability in the Alone – Charity Multipurpose Non-profit WordPress Theme (<=7.8.3) that allows unauthenticated attackers to upload plugin-like ZIPs containing web shells via an AJAX action, enabling remote code execution and site takeover; it has been actively exploited since 12 July 2025 with Wordfence observing over 120,900 exploitation attempts. The Centre for Cybersecurity Belgium and Wordfence recommend urgent patching to version 7.8.5 or later, enhanced monitoring/detection, and investigation/remediation of historic compromises using published IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
