← WordPress Vulnerabilities
WordPress security by component

betheme

betheme is a WordPress theme with 23 published CVE records in this archive. The latest tracked vulnerability was published Aug 26, 2026; the highest published CVSS base score is 9.9.

Theme slug: betheme

CVE-2026-6178: Betheme permits Contributor-level stored cross-site scripting

Betheme through 28.4 insufficiently sanitizes and escapes user-controlled attributes in the icon_box_2 shortcode. A Contributor or higher can store arbitrary script that executes whenever a visitor opens the affected page.

PublishedAug 26, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for betheme
Safe version
Aug 26, 2026 CVE-2026-6178
Betheme permits Contributor-level stored cross-site scripting
Betheme through 28.4 insufficiently sanitizes and escapes user-controlled attributes in the icon_box_2 shortcode. A Contributor or higher can store arbitrary script that executes whenever a visitor opens the affected page.
See mitigation notes
CVE6.4
NVDPending
Aug 06, 2026 CVE-2026-65548
Betheme permits Contributor-level remote code execution
Betheme through 28.4.2 contains a remote-code-execution flaw reachable by an authenticated Contributor. Successful exploitation permits server-side code execution. No fixed release is currently identified.
> 28.4.2
CVE9.9
NVDPending
May 05, 2026 CVE-2026-6262
Betheme: Filesystem traversal
Betheme is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 28.4.
See mitigation notes
CVE6.5
NVDPending
May 05, 2026 CVE-2026-6261
Betheme: Dangerous file upload
Betheme is affected by dangerous file upload. Exploitation requires an authenticated author account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 28.4.
See mitigation notes
CVE8.8
NVDPending
Dec 09, 2025 CVE-2025-63075
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 09, 2025 CVE-2025-9371
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 06, 2025 CVE-2025-7399
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 16, 2025 CVE-2025-3077
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 21, 2025 CVE-2025-0450
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 13, 2024 CVE-2024-5567
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 30, 2024 CVE-2024-3998
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 30, 2024 CVE-2024-2694
Betheme: Code execution
Betheme is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Jun 19, 2024 CVE-2023-39998
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVD7.2
Jun 19, 2024 CVE-2023-47770
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVDPending
Mar 25, 2024 CVE-2022-45356
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD8.8
Mar 25, 2024 CVE-2022-45352
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Mar 25, 2024 CVE-2022-45351
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Mar 25, 2024 CVE-2022-45349
Betheme: A security weakness
Betheme is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 10, 2023 CVE-2023-29101
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jan 14, 2023 CVE-2022-45353
Betheme: Broken access control
Betheme is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE4.3
NVD8.1
Nov 22, 2022 CVE-2022-45363
Betheme: Cross-site scripting
Betheme is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Nov 21, 2022 CVE-2022-3861
Betheme: Code execution
Betheme is affected by code execution. Exploitation requires an authenticated subscriber account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Nov 17, 2022 CVE-2022-45077
Betheme: Code execution
Betheme is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE6.3
NVD8.8