Skip to content

Known CVE

Unauthenticated Arbitrary Plugin Upload in Alone Theme

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3.

CVE-2025-5394

Critical2025

cve2025 · unauth · file-upload · rce · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website