8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload flow.
AI Analysis
Arbitrary File Upload vulnerability in Betheme theme for WordPress, allowing authenticated attackers to upload arbitrary files and achieve remote code execution
Basic Information
ID
CVE-2026-6261
Source
Wordfence
Published
May 5, 2026 at 11:25
Affected Product
Vendor
MuffinGroup
Product
Betheme
Affected Versions
MuffinGroup Betheme 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
MuffinGroup
Product
Betheme
Version
up to 28.4