Impact
The Betheme theme contains insufficient input sanitization for the ‘icon_box_2’ shortcode attributes. An authenticated WordPress user with contributor or higher privileges can embed arbitrary JavaScript that is stored in the content. When a visitor loads the page containing the injected shortcode, the malicious script executes in the visitor’s browser. This flaw enables code execution in the context of any visitor who views the affected page, potentially allowing the attacker to modify the user experience or exfiltrate data entered during the visit. The weakness is categorized as CWE‑79.
Affected Systems
All releases of the MuffinGroup Betheme WordPress theme up to and including version 28.4 are affected. The vulnerability is tied to the ‘icon_box_2’ shortcode and applies to every instance where that shortcode is used in content. A patch is provided in versions newer than 28.4, but no specific fixed version number is listed.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is considered medium severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed. The flaw requires an authenticated user with at least contributor role to inject the payload, after which the malicious script is stored and delivered to all site visitors who view the page containing the shortcode. The attack vector is therefore user‑initiated content injection and subsequent view of the affected content.
OpenCVE Enrichment