Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects Alone: from n/a through <= 7.8.2.
Published: 2025-07-04
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Alone theme contains a flaw that allows attackers to generate and execute arbitrary code through improper control of code generation (CWE‑94). This weakness enables remote code inclusion, giving attackers the ability to run any PHP code on the affected WordPress site, thereby compromising confidentiality, integrity, and availability.

Affected Systems

WordPress installations that use the Beplusthemes Alone theme in any version up to and including 7.8.2 are impacted. This applies to every site where the theme is active and has not been upgraded beyond 7.8.2.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for remote code execution presents a serious threat, especially for publicly accessible WordPress sites. Attackers could exploit the flaw via a remote request that triggers code inclusion through the activated theme, leading to full compromise of the affected system.

Generated by OpenCVE AI on April 30, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Alone theme to the latest patched version (7.9 or later).
  • If an immediate upgrade is not possible, deactivate or remove the theme until a patch is applied.
  • Deploy a Web Application Firewall rule or similar controls to block suspicious PHP input that the theme might attempt to execute, and disable file editing in the WordPress dashboard to harden the installation.

Generated by OpenCVE AI on April 30, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19994 Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2. Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects Alone: from n/a through <= 7.8.2.
Title WordPress Alone <= 7.8.2 - Arbitrary Code Execution Vulnerability WordPress Alone theme <= 7.8.2 - Arbitrary Code Execution Vulnerability
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Mon, 07 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.
Title WordPress Alone <= 7.8.2 - Arbitrary Code Execution Vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:17.420Z

Reserved: 2025-06-19T10:02:25.008Z

Link: CVE-2025-52718

cve-icon Vulnrichment

Updated: 2025-07-07T16:25:32.896Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T12:15:33.197

Modified: 2026-04-23T15:32:04.680

Link: CVE-2025-52718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:00:16Z

Weaknesses