VendorsMuffin Groupbethemeall versions
Vulnerabilities

Muffin Group Muffingroup Betheme 26.6 for Wordpress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-3861
Betheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection
Published 2022-11-21 · Modified
8.8EPSS 0.022
CVE-2022-45077
WordPress Betheme theme <= 26.5.1.4 - Auth. PHP Object Injection vulnerability
Published 2022-11-17 · Modified
8.8EPSS 0.007
CVE-2024-2694
Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection
Published 2024-08-30 · Analyzed
8.8EPSS 0.006
CVE-2022-45356
WordPress Betheme premium theme <= 26.6.1 - Broken Access Control vulnerability
Published 2024-03-25 · Modified
8.8EPSS 0.005
CVE-2023-39998
WordPress BeTheme theme <= 27.1.1 - Author+ Broken Access Control vulnerability
Published 2024-06-19 · Analyzed
8.2EPSS 0.005
CVE-2022-45353
WordPress Betheme theme <= 26.6.1 is vulnerable to Broken Access Control
Published 2023-01-14 · Modified
8.1EPSS 0.005
CVE-2023-47770
WordPress BeTheme theme <= 27.1.1 - Contributor+ Broken Access Control vulnerability
Published 2024-06-19 · Analyzed
7.6EPSS 0.003
CVE-2023-29101
WordPress Betheme Theme <= 26.7.5 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-10 · Modified
7.1EPSS 0.004
CVE-2024-5567
Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File
Published 2024-09-13 · Analyzed
6.4EPSS 0.003
CVE-2025-3077
Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-04-16 · Analyzed
6.4EPSS 0.003
CVE-2024-3998
Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-08-30 · Analyzed
6.4EPSS 0.003
CVE-2025-0450
Betheme <= 27.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
Published 2025-01-21 · Analyzed
6.4EPSS 0.002
CVE-2022-45351
WordPress Betheme premium theme <= 26.6.1 - Broken Access Control vulnerability
Published 2024-03-25 · Modified
5.4EPSS 0.005
CVE-2022-45363
WordPress Betheme premium theme <= 26.6.1 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published 2022-11-22 · Modified
5.4EPSS 0.004
CVE-2022-45352
WordPress Betheme premium theme <= 26.6.1 - Broken Access Control vulnerability
Published 2024-03-25 · Modified
5.4EPSS 0.004
CVE-2022-45349
WordPress Betheme premium theme <= 26.6.1 - Broken Access Control vulnerability
Published 2024-03-25 · Modified
4.3EPSS 0.004