CVE 8.8 HIGH

Betheme <= 28.4 - Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload_CVE-2026-6261

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload flow.

AI Analysis

Arbitrary File Upload vulnerability in Betheme theme for WordPress, allowing authenticated attackers to upload arbitrary files and achieve remote code execution

Basic Information

ID CVE-2026-6261
Source Wordfence
Published May 5, 2026 at 11:25

Affected Product

Vendor MuffinGroup
Product Betheme
Affected Versions MuffinGroup Betheme 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor MuffinGroup
Product Betheme
Version up to 28.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.