Description
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to insufficient input sanitization and output escaping of theme breadcrumbs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-10-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Theme
AI Analysis

Impact

Betheme is vulnerable to stored Cross‑Site Scripting because the page_title parameter is not properly sanitized when used in the theme’s breadcrumbs. Authenticated users with Contributor role or higher can inject arbitrary JavaScript that is stored in the page title and executed automatically whenever the page is accessed by any visitor. This attack allows attackers to steal session cookies, deface the site, or execute further malicious actions in the context of visiting users.

Affected Systems

All installations of the Betheme WordPress theme from its first public release through version 28.1.6 are affected. Sites running the theme on any WordPress installation with Contributor‑level access or higher are vulnerable to exploitation of this stored‑XSS flaw.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a currently low probability of exploitation. However, because the vulnerability requires only contributor privileges—a common role on many sites—the risk of in‑site XSS remains significant for administrators who have granted such permissions. The flaw is not yet listed in the CISA KEV catalog, but any user who injects malicious content can infect all subsequent visitors to the affected pages, potentially leading to credential theft or site defacement.

Generated by OpenCVE AI on April 20, 2026 at 19:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Betheme to 28.1.7 or later, which removes the unsanitized page_title handling.
  • If immediate upgrade is infeasible, disable or sanitize the breadcrumb feature that outputs page titles to prevent stored scripts from rendering.
  • Restrict Contributor or higher roles to trusted administrators, or remove the capability for these roles to edit page titles, so that only privileged users can change them.

Generated by OpenCVE AI on April 20, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Muffingroup
Muffingroup betheme
Wordpress
Wordpress wordpress
Vendors & Products Muffingroup
Muffingroup betheme
Wordpress
Wordpress wordpress

Thu, 09 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to insufficient input sanitization and output escaping of theme breadcrumbs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Betheme <= 28.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_title'
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Muffingroup Betheme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:34:16.131Z

Reserved: 2025-08-22T19:43:31.721Z

Link: CVE-2025-9371

cve-icon Vulnrichment

Updated: 2025-10-09T14:33:31.239Z

cve-icon NVD

Status : Deferred

Published: 2025-10-09T12:15:35.807

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-9371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T19:30:06Z

Weaknesses