Description
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Published: 2026-08-06
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Betheme WordPress theme contains a code injection flaw that allows an attacker with contributor privileges to execute arbitrary PHP code on the server. This vulnerability, which maps to CWE‑94, can lead to complete compromise of the site’s confidentiality, integrity, and availability, giving the attacker full control over the web application and underlying server environment.

Affected Systems

All installations of Muffingroup Betheme theme version 28.4.2 and earlier on WordPress sites are affected. The flaw is limited to the theme code and does not affect core WordPress components directly.

Risk and Exploitability

The high CVSS score of 9.9 indicates a critical severity, yet the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not yet listed in CISA’s KEV catalog, suggesting no public exploits are documented. The likely attack vector is via a contributor account or any user with editing capability, which can be used to inject the harmful code into the theme.

Generated by OpenCVE AI on August 6, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Betheme version 28.4.3 or later as soon as possible.
  • Verify all WordPress user accounts, especially contributors, and revoke unnecessary privileges or remove suspicious accounts.
  • Restrict or disable the theme’s editor interface until a patch is applied, and consider applying WAF rules to block malicious code injection patterns.

Generated by OpenCVE AI on August 6, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Muffingroup
Muffingroup betheme
Wordpress
Wordpress wordpress
Vendors & Products Muffingroup
Muffingroup betheme
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Title WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Muffingroup Betheme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:34.160Z

Reserved: 2026-07-22T08:54:17.066Z

Link: CVE-2026-65548

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:15:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')