Stored Cross-Site Scripting Vulnerability in Betheme WordPress Theme
CVE-2025-9371

6.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2025

What is CVE-2025-9371?

The Betheme theme for WordPress suffers from a Stored Cross-Site Scripting vulnerability, allowing authenticated users with Contributor-level access and higher to inject arbitrary scripts via the 'page_title' parameter. This weakness stems from inadequate input sanitization and output escaping in the theme's breadcrumb feature. Exploiting this vulnerability enables attackers to execute malicious scripts when users view affected pages, posing significant risks to user data and site integrity.

Affected Version(s)

Betheme * <= 28.1.6

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zbigniew Piotrak
.
CVE-2025-9371 : Stored Cross-Site Scripting Vulnerability in Betheme WordPress Theme