ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Asset and Hidden Finances Investigations
      • Bug Sweep TSCM Investigation
    • Cyber Security
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > Hackers actively exploit severe RCE in WordPress By myself theme
    Hackers actively exploit severe RCE in WordPress By myself theme
    30
    Jul
    • ForensicsS
    • 0 Comments

    Hackers actively exploit severe RCE in WordPress By myself theme

    Digital forensics

    digital forensics WordPress

    Risk actors are actively exploiting a severe unauthenticated arbitrary file add vulnerability within the WordPress theme ‘By myself,’ to attain remote code execution and make a elephantine establish of abode takeover.

    Wordfence is reporting the malicious project, asserting it has blocked over 120,000 exploitation attempts focused on its prospects.

    The WordPress security firm also stories that the assaults started so a lot of days earlier than public disclosure of the flaw, indicating that possibility actors are monitoring changelogs and patches to see trivially exploitable complications earlier than indicators are despatched to web establish of abode owners.

    The vulnerability, tracked under CVE-2025-5394, impacts all versions of By myself up to 7.8.3. The vendor, Bearsthemes, fastened it in By myself model 7.8.5, launched on June 16, 2025.

    The disaster stems from the theme’s ‘alone_import_pack_install_plugin()’ aim, which lacks nonce assessments and is exposed by the wp_ajax_nopriv_ hook.

    The aim permits plugin set up by AJAX, and accepts a remote provide URL within the POST records, enabling unauthenticated users to dwelling off plugin installations from remote URLs.

    In step with Wordfence, attackers leverage the flaw to be able to add webshells inner ZIP archives, deploy password-safe PHP backdoors that allow chronic remote characterize execution by HTTP requests, or salvage hidden administrator users.

    In some cases, the attackers even set up elephantine-featured file managers that give them total control over the positioning’s databases.

    Given the above, signs of compromise consist of the look of newest admin users, suspicious ZIP/plugin folders, and requests to ‘admin-ajax.php?action=alone_import_pack_install_plugin.’

    Wordfence logged tens of hundreds of exploitation attempts from the IP addresses 193.84.71.244, 87.120.92.24, 146.19.213.18, and 2a0b:4141:820:752::2, so these ought to be blocked straight.

    digital forensics Volume of exploitation attempts against Alone-powered sites
    Volume of exploitation attempts against By myself-powered web sites
    Offer: Wordfence

    By myself is a top charge theme with virtually 10,000 sales on the Envato market, primarily extinct by non-earnings comparable to charities, NGOs, fundraising organizations, and social organizations.

    Although Wordfence submitted a document to Bearsthemes as early as Might presumably presumably also unprejudiced 30, 2025, they didn’t hear support, so they escalated the disaster to the Envato team on June 12.

    Four days later, the seller launched a fastened model of By myself, v7.8.5, which is the suggested update target for all users.

    Closing month, any other top charge WordPress theme, Motors, became once centered by hackers who exploited a particular person validation flaw to hijack administrator accounts on susceptible web sites.


    digital forensics Wiz

    Digital forensics The Board Account Deck CISOs In actuality Use

    CISOs know that getting board aquire-in begins with a transparent, strategic look of how cloud security drives change payment.

    This free, editable board document deck helps security leaders gift possibility, affect, and priorities in certain change terms. Turn security updates into fundamental conversations and quicker decision-making within the boardroom.

    Be taught Extra

    • Tags

    • actively cybercrime email-fraud forensics|digital-forensics hackers Investigation malware online-scam phishing-attack private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • Ethiopian Migrants Face Kidnappings and Death, Leaving Within the aid of Heartbroken Households
    • Andrew Tate Hits TikTok & Zuckerberg’s Meta For $100M For Kicking Ex-Kickboxer Off Platforms Support In 2022: “It’s Correct Vs Inappropriate,” Accused Rapist Insists
    • Conservatives mock Comey over Taylor Swift video
    • The generation of AI hacking has arrived
    • Hackers unleash torrent from Norwegian dam, releasing 132 gallons per 2nd for four hours

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    Ethiopian Migrants Face Kidnappings and Death, Leaving Within the aid of Heartbroken Households
    Andrew Tate Hits TikTok & Zuckerberg’s Meta For $100M For Kicking Ex-Kickboxer Off Platforms Support In 2022: “It’s Correct Vs Inappropriate,” Accused Rapist Insists
    Conservatives mock Comey over Taylor Swift video
    August 17, 2025
    Conservatives mock Comey over Taylor Swift video

    Popular Tags

    administration Bongino calls Crypto Cyber cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity Department digital-forensics email-fraud Epstein FBI’s forensics|digital-forensics Former fraud hacker hackers Investigation Korea Korean Launches malware malwarefraud malwarephishing-attack Microsoft North online-scam online-scamphishing-attack orders Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe South suspect Trump warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO