Stored Cross-Site Scripting Vulnerability in Betheme for WordPress
CVE-2026-6178
6.4MEDIUM
What is CVE-2026-6178?
The Betheme theme for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access and above to exploit stored cross-site scripting (XSS). This occurs through the theme's 'icon_box_2' shortcode due to inadequate input sanitization and output escaping of user-supplied attributes. When successfully exploited, this vulnerability enables attackers to inject malicious web scripts, leading to potential unauthorized actions or data exposure whenever a user accesses the compromised pages.
Affected Version(s)
Betheme 0 <= 28.4