
🚨 CVE-2025-5393: Alone – Charity Multipurpose Non-... Unauthenticated file deletion via path traversal in WordPress charity theme - nuke wp-config.php for instant RCE, CVSS 9... https://zerodaysignal.com/vulnerability/CVE-2025-5393 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
CVE-2025-5393 is a high‑severity path‑traversal vulnerability in a WordPress charity theme that permits unauthenticated deletion of wp-config.php, enabling remote code execution; currently no patch or active exploitation has been reported.
