Impact
The Betheme WordPress theme is affected by a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping of an Elementor display setting. An attacker with Contributor‑level or higher access can inject arbitrary JavaScript that executes every time a user views the injected page, potentially compromising user accounts, enabling phishing, or distributing malware.
Affected Systems
The vulnerability exists in all MuffinGroup Betheme releases up to and including version 28.1.3. Users running any of these versions should consider themselves affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1 % points to a low probability of exploitation today. The vulnerability is not listed in CISA’s KEV catalog. Although the description specifies the requirement of authenticated Contributor‑level access, the attack path is inferred: an attacker first logs in, then injects script via Elementor settings, and finally relies on victim interaction with the affected page. No public exploit has been reported.
OpenCVE Enrichment
EUVD