Close Menu
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
Trending

India’s Confidence Crisis Curbs Financial Engagement Despite High Access

March 24, 2026

Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

March 24, 2026

March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

March 24, 2026

Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

March 24, 2026

Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

March 24, 2026

Claude AI Now Executes Tasks Directly on macOS Devices

March 24, 2026

Trump Halts Iran Strikes for 5 Days Amid Talk Claims

March 24, 2026
Facebook X (Twitter) Instagram
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
VernoNews
Home»Technology»Hackers goal crucial WordPress theme flaw – tons of of websites in danger from potential takeover, discover out in the event you’re affected
Technology

Hackers goal crucial WordPress theme flaw – tons of of websites in danger from potential takeover, discover out in the event you’re affected

VernoNewsBy VernoNewsJuly 31, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
Hackers goal crucial WordPress theme flaw – tons of of websites in danger from potential takeover, discover out in the event you’re affected
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

[ad_1]


  • Alone – Charity Multipurpose Non-profit WordPress Theme has a 9.8/10 flaw
  • The bug permits crooks to create rogue admin accounts
  • Greater than 120,000 takeover makes an attempt already blocked

The “Alone – Charity Multipurpose Non-profit WordPress Theme”, a business theme utilized in many WordPress web sites, contained a crucial vulnerability that allowed risk actors to utterly take over the web site, specialists have warned.

The WordPress theme, designed for charities, NGOs, and fundraising campaigns, options greater than 40 ready-to-use demos, donation integration, and compatibility with Elementor and WPBakery.

Based on Themetix, round 200 lively WordPress websites are working this theme right now.


You might like

Ongoing assaults

Wordfence researchers declare exploitation began on July 12, two days earlier than the vulnerability was publicly disclosed. To this point, the corporate blocked greater than 120,000 exploitation makes an attempt from nearly a dozen completely different IP addresses.

Within the assaults, the risk actors attempt to add a ZIP archive with a PHP-based backdoor that grants them distant code execution capabilities, in addition to the power to add arbitrary information. Crooks additionally used the flaw to ship backdoors that may create extra admin accounts.

All variations as much as 7.8.3 contained a vulnerability that allowed risk actors to add arbitrary information, together with malware that may create admin accounts. That method, crooks can utterly take over web sites and use them to host different malware, redirect guests to different malicious pages, serve phishing touchdown pages, and extra.

The vulnerability is now tracked as CVE-2025-4394, and has a severity rating of 9.8/10 (crucial). It was addressed in model 7.8.5, which was launched on June 16, 2025. In case you are utilizing this theme, it will be smart to replace it as quickly as potential, for the reason that bug is being actively exploited within the wild.

Signal as much as the TechRadar Professional e-newsletter to get all the highest information, opinion, options and steerage your online business must succeed!

WordPress is usually thought-about a protected web site builder platform, however third-party themes and plugins – not a lot. That’s the reason safety professionals advise WordPress customers to solely hold the plugins and themes they actively use, and to ensure they’re all the time updated.

By way of The Hacker Information

You may also like

[ad_2]

Avatar photo
VernoNews

    Related Posts

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    iPhone Air C1X Modem Matches Qualcomm X80, Leads in 5G Latency

    March 23, 2026

    5 GEO Strategies to Boost Brand Visibility in AI Search 2026

    March 23, 2026
    Leave A Reply Cancel Reply

    Don't Miss
    Business

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    By VernoNewsMarch 24, 20260

    India’s financial sector provides widespread access to products, yet a confidence crisis among consumers hampers…

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    Trump Halts Iran Strikes for 5 Days Amid Talk Claims

    March 24, 2026
    About Us
    About Us

    VernoNews delivers fast, fearless coverage of the stories that matter — from breaking news and politics to pop culture and tech. Stay informed, stay sharp, stay ahead with VernoNews.

    Our Picks

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    March 24, 2026

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026
    Trending

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026
    • Contact Us
    • Privacy Policy
    • Terms of Service
    2025 Copyright © VernoNews. All rights reserved

    Type above and press Enter to search. Press Esc to cancel.