Impact
The Alone theme contains a flaw that allows attackers to generate and execute arbitrary code through improper control of code generation (CWE‑94). This weakness enables remote code inclusion, giving attackers the ability to run any PHP code on the affected WordPress site, thereby compromising confidentiality, integrity, and availability.
Affected Systems
WordPress installations that use the Beplusthemes Alone theme in any version up to and including 7.8.2 are impacted. This applies to every site where the theme is active and has not been upgraded beyond 7.8.2.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for remote code execution presents a serious threat, especially for publicly accessible WordPress sites. Attackers could exploit the flaw via a remote request that triggers code inclusion through the activated theme, leading to full compromise of the affected system.
OpenCVE Enrichment
EUVD