info: name: Unauthenticated Arbitrary Plugin Upload in Alone Theme author: Nxploited,DhiyaneshDK severity: critical description: | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. impact: | This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. remediation: Fixed in7.8.5. reference: - https://github.com/Nxploited/CVE-2025-5394/tree/main - https://x.com/cloudflare/status/1951319364856058035?s=46 metadata: verified:true max-request:1 publicwww-query:"/wp-content/themes/alone/" fofa-query: body="/wp-content/themes/alone/" tags: cve,cve2025,unauth,file-upload,intrusive,rce