Close Menu
Daily View
  • Home
  • News
    • World
    • UK
    • US
  • The View
  • Sport
  • Culture
  • Lifestyle
  • Business
  • Tech
What's Hot

The “talented” Tottenham player is leaving with his son

August 3, 2025

Malicious activity spikes precede new security flaws in 80% of cases

August 3, 2025

US Federal Reserve Governor resigns from a location opened for Trump’s appointees

August 3, 2025
Facebook X (Twitter) Instagram
Trending
  • The “talented” Tottenham player is leaving with his son
  • Malicious activity spikes precede new security flaws in 80% of cases
  • US Federal Reserve Governor resigns from a location opened for Trump’s appointees
  • The Knicks now shift their head coaching search to Mike Brown and Taylor Jenkins
  • Trump’s new tariff regime began after months of confusion and uncertainty. But is his approach working?
  • Why America wins energy innovation
  • Love in the Age of WhatsApp – Philosophers explain how technology reduces the power of relationships
  • Children’s vaccination rates have been the lowest rating in over 10 years – why?
  • Subscribe to Newsletter
  • Advertise with Us
  • Support Us
Facebook X (Twitter)
Daily ViewDaily View
Button
Sunday, August 3
  • Home
  • News
    1. World
    2. UK
    3. US
    4. View All

    Why America wins energy innovation

    August 3, 2025

    India suggests that it will continue to buy Russian oil despite Trump’s threat

    August 3, 2025

    “A little confidence” We Gaza delegation will see the big picture

    August 2, 2025

    Judges allow the National Science Foundation to withhold hundreds of millions of research dollars

    August 2, 2025

    Children’s vaccination rates have been the lowest rating in over 10 years – why?

    August 3, 2025

    Clampdown of social media ads at Channel Crossing has been announced

    August 3, 2025

    BBC responds as two strictly cam dance stars accused of taking cocaine

    August 3, 2025

    The crowd attends the mother’s funeral and children shot in Northern Ireland

    August 2, 2025

    US Federal Reserve Governor resigns from a location opened for Trump’s appointees

    August 3, 2025

    The man tries to explode 14 explosive devices while being arrested by police

    August 3, 2025

    Trump is no longer thinking about Diddycomb’s pardon

    August 3, 2025

    World champion Sprinter has been arrested for allegedly assaulting his boyfriend

    August 2, 2025

    US Federal Reserve Governor resigns from a location opened for Trump’s appointees

    August 3, 2025

    Why America wins energy innovation

    August 3, 2025

    Children’s vaccination rates have been the lowest rating in over 10 years – why?

    August 3, 2025

    Clampdown of social media ads at Channel Crossing has been announced

    August 3, 2025
  • The View
  • Sport
  • Culture
  • Lifestyle
  • Business
  • Tech
Daily View
Home»Tech

Hackers actively utilize important RCEs with WordPress-only themes

July 31, 2025 Tech 2 Mins Read
Hackers actively utilize important RCEs with WordPress-only themes
Volume of exploitation attempts against Alone-powered sites
Source: Wordfence
Share
Facebook Twitter LinkedIn Pinterest Email

Risk actors are actively exploiting the “single” crucial unauthenticated arbitrary file add vulnerability in WordPress themes to allow distant code execution and full website takeover.

WordFence reported malicious exercise and mentioned it blocked greater than 120,000 makes an attempt to take advantage of the corporate focused at its prospects.

The WordPress safety firm additionally reported that the assault began just a few days earlier than the publication of the grievance, indicating that risk actors are monitoring changelogs and patches to find minor, exploitable points earlier than alerts are despatched to the web site proprietor.

Vulnerabilities tracked in CVE-2025-5394 have an effect on all variations alone as much as 7.8.3. Vendor Bearsthemes fastened it in model 7.8.5, launched on June 16, 2025.

The issue comes from the theme “alone_import_pack_install_plugin()”.

This operate permits the set up of plugins by means of AJAX, accepting distant supply URLs in POST information, permitting unauthenticated customers to set off plugins set up from the distant URL.

In accordance with WordFence, attackers can leverage Flaw to add internet shells inside ZIP Archives, deploy password-protected PHP backdoors that permit persistent distant command execution by way of HTTP requests, or create hidden admin customers.

In some instances, an attacker installs a full-featured file supervisor that gives full management over the location’s database.

Given the above, indicators of compromise embody the looks of the brand new admin person, the suspicious zip/plugin folder, and a request to “admin-ajax.php?motion=alone_import_pack_install_plugin”.

Wordfence recorded tens of 1000’s of exploitation makes an attempt from IP addresses 193.84.71.244, 87.120.92.24, 146.19.213.18, and 2A0b:4141:820:752 ::2, and due to this fact these must be blocked instantly.

Amount of exploitation attempts against a single site
Quantity of exploitation makes an attempt in opposition to a single website
Supply: Wordfence

Solely, it’s a premium theme with round 10,000 gross sales within the Enbato market, which is primarily utilized by nonprofit organizations resembling charities, NGOs, fundraising organizations, and social organizations.

See also  Windows 11 Gets a New Black Death Screen, Auto Recovery Tool

Wordfence submitted a report back to Bearsthemes as early as Might 30, 2025, however they didn’t reply, and on June 12, the problem escalated to the Envato staff.

4 days later, the seller launched its fastened model v7.8.5 by itself. That is the really helpful replace goal for all customers.

Final month, Motors, one other premium WordPress theme, was focused by hackers who exploited a flaw in person verification to hijack an administrator account on a weak web site.

News Tech

Keep Reading

Malicious activity spikes precede new security flaws in 80% of cases

US Federal Reserve Governor resigns from a location opened for Trump’s appointees

Children’s vaccination rates have been the lowest rating in over 10 years – why?

Clampdown of social media ads at Channel Crossing has been announced

The man tries to explode 14 explosive devices while being arrested by police

Russian hackers use ISP access to hack embassy in AITM attacks

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

It’s official: Marvel doesn’t know what’s wrong with himself

July 20, 2025

Chelsea discusses to sign a “exceptional” £52 million ace

July 20, 2025

Duke’s Cooper Flag declares “best decision in hindsight” for the 2025 NBA Draft

July 20, 2025

What should I do to see wildlife in a national park?

July 20, 2025
Latest Posts

The “talented” Tottenham player is leaving with his son

August 3, 2025

Malicious activity spikes precede new security flaws in 80% of cases

August 3, 2025

US Federal Reserve Governor resigns from a location opened for Trump’s appointees

August 3, 2025
dailyview
Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

Topics

  • News
  • Business
  • Culture
  • Lifestyle
  • Sport

Topics

  • World
  • UK News
  • USA News
  • Tech

Pages

  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

Editors Picks

Chelsea discusses to sign a “exceptional” £52 million ace

Duke’s Cooper Flag declares “best decision in hindsight” for the 2025 NBA Draft

What should I do to see wildlife in a national park?

© 2025 All Rights reserved | Powered by Dailyview

Type above and press Enter to search. Press Esc to cancel.