logo

Warning: A critical vulnerability in the Alone-Charity Multipurpose Non-profit WordPress Theme is currently being actively exploited. Patch Immediately!

ID: 1057a7cb-5c0f-5da9-ab0c-e72bda30f95f

STIX ID: report--1057a7cb-5c0f-5da9-ab0c-e72bda30f95f

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-07-24

...
...

CVE-2025-5394 is a critical (CVSS 9.8) arbitrary file upload vulnerability in the Alone – Charity Multipurpose Non-profit WordPress Theme (<=7.8.3) that allows unauthenticated attackers to upload plugin-like ZIPs containing web shells via an AJAX action, enabling remote code execution and site takeover; it has been actively exploited since 12 July 2025 with Wordfence observing over 120,900 exploitation attempts. The Centre for Cybersecurity Belgium and Wordfence recommend urgent patching to version 7.8.5 or later, enhanced monitoring/detection, and investigation/remediation of historic compromises using published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.