Impact
The Betheme WordPress theme contains a code injection flaw that allows an attacker with contributor privileges to execute arbitrary PHP code on the server. This vulnerability, which maps to CWE‑94, can lead to complete compromise of the site’s confidentiality, integrity, and availability, giving the attacker full control over the web application and underlying server environment.
Affected Systems
All installations of Muffingroup Betheme theme version 28.4.2 and earlier on WordPress sites are affected. The flaw is limited to the theme code and does not affect core WordPress components directly.
Risk and Exploitability
The high CVSS score of 9.9 indicates a critical severity, yet the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not yet listed in CISA’s KEV catalog, suggesting no public exploits are documented. The likely attack vector is via a contributor account or any user with editing capability, which can be used to inject the harmful code into the theme.
OpenCVE Enrichment