Reflected XSS Vulnerability in Muffingroup Betheme
CVE-2026-94415

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-94415?

Muffingroup's Betheme is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw allows attackers to manipulate user inputs on web pages to execute malicious scripts in the context of the user's browser. The affected versions span from an unspecified release to version 28.5.8, potentially jeopardizing the security of websites utilizing this theme. It is essential for site administrators to implement mitigation strategies to avoid exploitation through unvalidated input that could lead to unauthorized actions.

Affected Version(s)

Betheme 0 <= 28.5.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad | Patchstack Bug Bounty Program
.