Loading HuntDB...

GHSA-jg98-c5j8-6598

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.

Related CVEs

Key Information

GHSA ID
GHSA-jg98-c5j8-6598
Published
July 15, 2025 6:30 AM
Last Modified
July 15, 2025 6:30 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.