Description
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.
Published: 2025-07-15
Score: 9.8 Critical
EPSS: 52.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Alone – Charity Multipurpose Non‑profit WordPress Theme allows an unauthenticated user to upload ZIP archives because the function alone_import_pack_install_plugin() lacks a capability check. If the attacker places a malicious file such as a webshell inside the archive, the theme will extract it during the import, and the code will run on the server, giving the attacker full remote code execution.

Affected Systems

All releases of the Bearsthemes Alone – Charity Multipurpose Non‑profit WordPress Theme up to and including version 7.8.3 are vulnerable. Sites that continue using the theme and have not removed the import feature or updated the theme remain at risk.

Risk and Exploitability

With a CVSS score of 9.8 and an EPSS score of 52%, this vulnerability is critical and likely to be exploited in the wild. It is not yet listed in the CISA KEV catalog. The attack vector is network‑based: an unauthenticated attacker can reach the theme’s upload endpoint and supply a crafted ZIP file. The missing authorization check corresponds to CWE‑862, allowing unauthenticated arbitrary file uploads that lead to remote code execution.

Generated by OpenCVE AI on August 25, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or delete the plugin import endpoint so that unauthenticated users cannot trigger the function.
  • Configure a web application firewall or server rule to reject ZIP uploads unless the request is authenticated as an administrator.
  • Monitor the site for unexpected file uploads or execution patterns and investigate any anomalies immediately.
  • Contact the vendor or review the theme’s update channel for a release that addresses this issue and upgrade as soon as a patch becomes available.

Generated by OpenCVE AI on August 25, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Description The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.

Tue, 15 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00183}


Tue, 15 Jul 2025 04:00:00 +0000

Type Values Removed Values Added
Description The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
Title Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:04:57.436Z

Reserved: 2025-05-30T16:01:34.027Z

Link: CVE-2025-5394

cve-icon Vulnrichment

Updated: 2025-07-15T13:37:55.417Z

cve-icon NVD

Status : Deferred

Published: 2025-07-15T04:15:55.200

Modified: 2026-06-17T09:47:50.280

Link: CVE-2025-5394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:30:05Z

Weaknesses