Thème WordPress

Vulnérabilités Betheme

Cette page rassemble les failles publiées pour Betheme, leurs plages de versions affectées et les correctifs signalés dans la base locale.

21Vulnérabilités
0Critiques
20Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Betheme

21 fiches

CVE-2024-5567 Moyenne · 6,4
Betheme

Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.5 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-27.5.5

Correctif

27.5.6

Publication

12/09/2024

CVE-2024-3998 Moyenne · 6,4
Betheme

Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-27.5.6

Correctif

Non indiqué

Publication

29/08/2024

CVE-2023-47770 Moyenne · 6,3
Betheme

Betheme <= 27.1.1 – Missing Authorization

The Betheme theme for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 27.1.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-27.1.1

Correctif

27.1.2

Publication

14/11/2023

CVE-2023-29101 Moyenne · 6,1
Betheme

Betheme <= 26.7.5 – Reflected Cross-Site Scripting

The Betheme theme for WordPress is vulnerable to Reflected Cross-Site Scripting on shop pages in versions up to, and including, 26.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-26.7.5

Correctif

26.8

Publication

13/04/2023

CVE-2022-3861 Élevée · 8,8
Betheme

Betheme <= 26.5.1.4 – Authenticated (Subscriber+) PHP Object Injection

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage,…

Versions affectées

*-26.5.1.4

Correctif

26.6

Publication

18/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités