theme

Alone Vulnerabilities

10 known security issues reported for the Alone WordPress theme. Most recent disclosed Oct 22, 2025.

5 critical

Running Alone on your site? Check whether your installed version is affected.

Scan your site free

Alone [alone] <= 7.8.3 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through <= 7.8.3.

Affected:
up to 7.8.3
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-60206 on NVD →

Alone [alone] < 7.8.5

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Code Injection. This issue affects Alone: from n/a through n/a.

Affected:
up to 7.8.5
Fixed in:
7.8.5
Disclosed:
Aug 20, 2025

CVE-2025-54019 on NVD →

Alone < 7.8.5 - Unauthenticated Remote Code Execution

critical

The Alone theme for WordPress is vulnerable to Remote Code Execution in versions up to 7.8.5. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for unauthenticated attackers to execute arbitrary code on the server.

CVSS:
9.8
Affected:
up to 7.8.5
Fixed in:
7.8.5
Disclosed:
Aug 2, 2025

CVE-2025-54019 on NVD →

Alone <= 7.8.3 - Unauthenticated Remote Code Execution

critical

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 7.8.3
Fix:
No patched version reported
Disclosed:
Jul 16, 2025

CVE-2025-60206 on NVD →

Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File Deletion

critical

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to delete a...

CVSS:
9.1
Affected:
up to 7.8.5
Fixed in:
7.8.7
Disclosed:
Jul 14, 2025

CVE-2025-5393 on NVD →

Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation

critical

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip fil...

CVSS:
9.8
Affected:
up to 7.8.3
Fixed in:
7.8.5
Disclosed:
Jul 14, 2025

CVE-2025-5394 on NVD →

Alone [alone] < 7.8.5

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.

Affected:
up to 7.8.5
Fixed in:
7.8.5
Disclosed:
Jul 4, 2025

CVE-2025-52718 on NVD →

Alone <= 7.8.2 - Unauthenticated Remote Code Execution

critical

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.8.2. This makes it possible for unauthenticated attackers to execute code on the server. CVE-2025-54019 may be a duplicate of this issue, it is unclear how there...

CVSS:
9.8
Affected:
up to 7.8.2
Fixed in:
7.8.5
Disclosed:
Jul 1, 2025

CVE-2025-52718 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database