PT-2025-29897 · Alone+1 · Alone+1

Trương Hữu Phúc

+1

·

Published

2025-07-17

·

Updated

2025-07-22

·

CVE-2025-5396

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bears Backup versions prior to 2.0.1
Description The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.0.0. This is due to the bbackup ajax handle() function lacking capability checks and proper validation of user-supplied input, which is directly passed to call user func(). This allows unauthenticated attackers to execute code on the server, potentially enabling them to inject backdoors or create new administrative user accounts. On WordPress sites using the Alone theme version 7.8.4 and older, this issue can be chained with another vulnerability to install the Bears Backup plugin and achieve the same impact.
Recommendations Update to Bears Backup version 2.0.1 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5396

Affected Products

Alone
Bears Backup