Hackers target critical WordPress theme flaw – hundreds of sites at risk from potential takeover, find out if you’re affected
- Alone – Charity Multipurpose Non-profit WordPress Theme has a 9.8/10 flaw
- The bug allows crooks to create rogue admin accounts
- More than 120,000 takeover attempts already blocked
The “Alone – Charity Multipurpose Non-profit WordPress Theme”, a commercial theme used in many WordPress websites, contained a critical vulnerability that allowed threat actors to completely take over the website, experts have warned.
The WordPress theme, designed for charities, NGOs, and fundraising campaigns, features more than 40 ready-to-use demos, donation integration, and compatibility with Elementor and WPBakery.
According to Themetix, around 200 active WordPress sites are running this theme today.
Ongoing attacks
Wordfence researchers claim exploitation started on July 12, two days before the vulnerability was publicly disclosed. So far, the company blocked more than 120,000 exploitation attempts from almost a dozen different IP addresses.
In the attacks, the threat actors try to upload a ZIP archive with a PHP-based backdoor that grants them remote code execution capabilities, as well as the ability to upload arbitrary files. Crooks also used the flaw to deliver backdoors that can create additional admin accounts.
All versions up to 7.8.3 contained a vulnerability that allowed threat actors to upload arbitrary files, including malware that can create admin accounts. That way, crooks can completely take over websites and use them to host other malware, redirect visitors to other malicious pages, serve phishing landing pages, and more.
The vulnerability is now tracked as CVE-2025-4394, and has a severity score of 9.8/10 (critical). It was addressed in version 7.8.5, which was released on June 16, 2025. If you are using this theme, it would be wise to update it as soon as possible, since the bug is being actively exploited in the wild.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
WordPress is generally considered a safe website builder platform, but third-party themes and plugins – not so much. That is why security pros advise WordPress users to only keep the plugins and themes they actively use, and to make sure they are always up to date.
Via The Hacker News
You might also like
Alone – Charity Multipurpose Non-profit WordPress Theme has a 9.8/10 flaw The bug allows crooks to create rogue admin accounts More than 120,000 takeover attempts already blocked The “Alone – Charity Multipurpose Non-profit WordPress Theme”, a commercial theme used in many WordPress websites, contained a critical vulnerability that allowed threat…
Recent Posts
- How to watch World Cup final replay – it’s spoiler-free
- The Kodak EC35 is a pocketable, beginner-friendly 35mm film camera
- This unpronounceable series of glyphs is an incredible side project from Kieran Hebden (aka Four Tet)
- Kodak EC35 is a dirt-cheap point-and-shoot film camera
- NASA shares beautiful timelapse of the Psyche spacecraft’s view over Mars
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023