Alone Charity Multipurpose Non-Profit WordPress Theme Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing unauthenticated arbitrary file deletion has been identified in the Alone – Charity Multipurpose Non-profit WordPress Theme, all versions through 7.8.3. This issue arises from inadequate file path validation in the alone_import_pack_restore_data() function. The flaw enables attackers to delete arbitrary files on the server, potentially leading to remote code execution if critical files, such as wp-config.php, are removed.

Impact

Exploitation of this vulnerability could result in unauthorized deletion of files on the server, with the potential for remote code execution if a sensitive file is deleted.

Remediation

Users are advised to update the theme to version 7.8.5 or a newer patched version.

Added: Jul 15, 2025, 4:18 AM
Updated: Jul 15, 2025, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.