Hackers are actively exploiting a critical unauthenticated arbitrary file upload in the WordPress theme “Alone”in order to achieve remote code execution (RCE) and gain complete control of the website.
See also: Cisco: ISE RCE vulnerabilities are being exploited in attacks

Wordfence reports this malicious activity, noting that it has blocked over 120,000 exploit attempts targeting its customers.
The WordPress security firm also notes that the attacks began several days before the vulnerability was publicly disclosed, suggesting that the attackers are monitoring software changes and updates to identify vulnerabilities that can be easily exploited before website administrators have a chance to be notified
The vulnerability is tracked as CVE-2025-5394 and affects all versions of the Alone theme up to and including 7.8.3. The theme's developer, Bearsthemes, fixed the issue in version 7.8.5, released on June 16, 2025. The issue stems from the alone_import_pack_install_plugin() , which does not include nonce checks and is exposed via the wp_ajax_nopriv_.
This function allows for the installation of plugins via AJAX, accepting a remote URL as part of the POST data, which allows unauthorized users to initiate plugin installations from remote locations.
According to Wordfence, attackers are exploiting this vulnerability to upload webshells inside ZIP files, install password-protected PHP backdoors for continuous remote command execution via HTTP requests, or even create hidden administrators on the site. In some cases, attackers go as far as installing fully functional file managers, gaining complete control over the site's databases.
See also: New Fortinet FortiWeb breaches linked to public RCE exploits

Based on the above, indications of a breach include: The appearance of new administrators in the system, suspicious ZIP or add-on folders, requests to the file admin-ajax.php?action=alone_import_pack_install_plugin
Wordfence has recorded tens of thousands of exploitation attempts from the IP addresses: 193.84.71.244 87.120.92.24 146.19.213.18 2a0b:4141:820:752::2. The IPs should be immediately blocked from the website's security systems.
Alone is a premium WordPress theme with nearly 10,000 sales on the Envato platform, and is primarily used by non-profit organizations such as charities, NGOs, fundraising organizations, and social initiatives.
Although Wordfence had reported the issue to Bearsthemes since May 30, 2025, it had not received a response. So, on June 12, it escalated the issue to the Envato team. Four days later, the vendor released the patched Alone v7.8.5, which is the recommended update for all users of the theme.
See also: Vulnerability in Symantec Endpoint Management Suite allows RCE execution
Last month, another premium WordPress theme, Motors, was targeted in attacks in which hackers exploited a user authentication vulnerability to gain access to administrator accounts on vulnerable websites.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
