logo

Hackers actively exploit critical RCE in WordPress Alone theme

ID: 20b10b40-73a7-5f61-b5d5-708ebd30349e

STIX ID: report--20b10b40-73a7-5f61-b5d5-708ebd30349e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-07-30

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

**Active exploitation of CVE-2025-5394 in the WordPress 'Alone' theme enables unauthenticated arbitrary plugin installation via admin-ajax.php, leading to remote code execution, webshell/backdoor deployment, hidden admin account creation, and full site takeover; Wordfence blocked over 120,000 attempts and identified multiple attacker IPs, and Bearsthemes released a patch (Alone v7.8.5) on 2025-06-16.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.