The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3.
id: CVE-2025-5394
info:
name: Unauthenticated Arbitrary Plugin Upload in Alone Theme
author: Nx
...