# Alone--Charity多功能非营利WordPress主题<= 7.8.3-由于插件安装,未经授权上传任意文件
## 概述
Alone – Charity Multipurpose Non-profit WordPress Theme主题在WordPress中的任意文件上传漏洞,由于`alone_import_pack_install_plugin()`函数缺少能力检查,导致未认证的攻击者可以从远程位置上传包含webshell的zip文件,实现远程代码执行。
## 影响版本
所有版本,包括7.8.3及以前版本。
## 细节
`alone_import_pack_install_plugin()`函数缺少必要的权限检查。攻击者可以上传伪装成插件的zip文件,从而使这些文件被执行,进而实现远程代码执行。
## 影响
未认证的攻击者可以通过上传包含webshell的zip文件,实现远程代码执行。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | CVE‑2025‑5394 WP Alone ≤ 7.8.3 | https://github.com/fokda-prodz/CVE-2025-5394 | POC详情 |
2 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5394.yaml | POC详情 |
3 | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation | https://github.com/Nxploited/CVE-2025-5394 | POC详情 |
4 | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation | https://github.com/Yucaerin/CVE-2025-5394 | POC详情 |
标题: Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation -- 🔗来源链接
标签:
神龙速读暂无评论