HomeSecurityHackers actively exploit critical RCE in WordPress Alone

Hackers actively exploit critical RCE in WordPress Alone

Hackers are actively exploiting a critical unauthenticated arbitrary file upload in the WordPress theme “Alone”in order to achieve remote code execution (RCE) and gain complete control of the website.

See also: Cisco: ISE RCE vulnerabilities are being exploited in attacks

WordPress Alone RCE

Wordfence reports this malicious activity, noting that it has blocked over 120,000 exploit attempts targeting its customers.

The WordPress security firm also notes that the attacks began several days before the vulnerability was publicly disclosed, suggesting that the attackers are monitoring software changes and updates to identify vulnerabilities that can be easily exploited before website administrators have a chance to be notified

The vulnerability is tracked as CVE-2025-5394 and affects all versions of the Alone theme up to and including 7.8.3. The theme's developer, Bearsthemes, fixed the issue in version 7.8.5, released on June 16, 2025. The issue stems from the alone_import_pack_install_plugin() , which does not include nonce checks and is exposed via the wp_ajax_nopriv_.

This function allows for the installation of plugins via AJAX, accepting a remote URL as part of the POST data, which allows unauthorized users to initiate plugin installations from remote locations.

According to Wordfence, attackers are exploiting this vulnerability to upload webshells inside ZIP files, install password-protected PHP backdoors for continuous remote command execution via HTTP requests, or even create hidden administrators on the site. In some cases, attackers go as far as installing fully functional file managers, gaining complete control over the site's databases.

See also: New Fortinet FortiWeb breaches linked to public RCE exploits

Hackers actively exploit critical RCE in WordPress Alone
Hackers actively exploit critical RCE in WordPress Alone

Based on the above, indications of a breach include: The appearance of new administrators in the system, suspicious ZIP or add-on folders, requests to the file admin-ajax.php?action=alone_import_pack_install_plugin

Wordfence has recorded tens of thousands of exploitation attempts from the IP addresses: 193.84.71.244 87.120.92.24 146.19.213.18 2a0b:4141:820:752::2. The IPs should be immediately blocked from the website's security systems.

Alone is a premium WordPress theme with nearly 10,000 sales on the Envato platform, and is primarily used by non-profit organizations such as charities, NGOs, fundraising organizations, and social initiatives.

Although Wordfence had reported the issue to Bearsthemes since May 30, 2025, it had not received a response. So, on June 12, it escalated the issue to the Envato team. Four days later, the vendor released the patched Alone v7.8.5, which is the recommended update for all users of the theme.

See also: Vulnerability in Symantec Endpoint Management Suite allows RCE execution

Last month, another premium WordPress theme, Motors, was targeted in attacks in which hackers exploited a user authentication vulnerability to gain access to administrator accounts on vulnerable websites.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS