Muffin Group Betheme
cpe:2.3:a:muffingroup:betheme:*:*:*:*:wordpress:*:*
- <= 28.4
A vulnerability allowing arbitrary file upload has been identified in the Betheme WordPress theme, affecting versions through 28.4. The issue arises from the upload_icons() function, which improperly handles user-uploaded ZIP files by moving and extracting them into a public uploads directory without validating the file types. This flaw enables authenticated attackers with author-level access or higher to upload arbitrary files, including PHP scripts, which could then be executed remotely. The vulnerability is exploited through the Icons icon-pack upload feature.
Exploitation of this vulnerability allows for arbitrary file upload, including PHP files, leading to remote code execution on the server.
Users are advised to update to Betheme version 28.4.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.