Muffingroup
Muffingroup Betheme: vulnerabilidades y CVE
Muffingroup Betheme tiene 23 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6178 | Media (6.4) | 0.36% | — | 26 ago 2026 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due to insufficient input sanitization and output escaping… |
| CVE-2026-65548 | Crítica (9.9) | 0.79% | — | 6 ago 2026 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. |
| CVE-2026-6262 | Media (6.5) | 0.42% | — | 5 may 2026 | The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path… |
| CVE-2026-6261 | Alta (8.8) | 0.79% | — | 5 may 2026 | The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a… |
| CVE-2025-63075 | Media (6.5) | 0.20% | — | 9 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in muffingroup Betheme betheme allows DOM-Based XSS.This issue affects Betheme: from n/a through <= 28.2. |
| CVE-2025-9371 | Media (6.4) | 0.19% | — | 9 oct 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to insufficient input sanitization and output escaping of… |
| CVE-2025-7399 | Media (6.4) | 0.20% | — | 6 ago 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due to insufficient input sanitization and output escaping. This… |
| CVE-2025-3077 | Media (5.4) | 0.28% | — | 16 abr 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and… |
| CVE-2025-0450 | Media (5.4) | 0.24% | — | 21 ene 2025 | The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output… |
| CVE-2024-5567 | Media (5.4) | 0.32% | — | 13 sept 2024 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-3998 | Media (5.4) | 0.26% | — | 30 ago 2024 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping… |
| CVE-2024-2694 | Alta (8.8) | 0.62% | — | 30 ago 2024 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible… |
| CVE-2023-39998 | Alta (7.2) | 0.46% | — | 19 jun 2024 | Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1. |
| CVE-2023-47770 | Alta (7.6) | 0.29% | — | 19 jun 2024 | Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1. |
| CVE-2022-45356 | Alta (8.8) | 0.54% | — | 25 mar 2024 | Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. |
| CVE-2022-45352 | Media (4.3) | 0.40% | — | 25 mar 2024 | Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. |
| CVE-2022-45351 | Media (5.4) | 0.46% | — | 25 mar 2024 | Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. |
| CVE-2022-45349 | Media (4.3) | 0.40% | — | 25 mar 2024 | Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. |
| CVE-2023-29101 | Media (6.1) | 0.38% | — | 10 may 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions. |
| CVE-2022-45353 | Alta (8.1) | 0.50% | — | 14 ene 2023 | Broken Access Control in Betheme theme <= 26.6.1 on WordPress. |
| CVE-2022-45363 | Media (5.4) | 0.41% | — | 22 nov 2022 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress. |
| CVE-2022-3861 | Alta (8.8) | 2.2% | — | 21 nov 2022 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and… |
| CVE-2022-45077 | Alta (8.8) | 0.67% | — | 17 nov 2022 | Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.