Thème WordPress

Vulnérabilités Betheme

Cette page rassemble les failles publiées pour Betheme, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
23Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Betheme

24 fiches

CVE-2024-5647 Moyenne · 6,4
Betheme

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-28.4

Correctif

28.4.1

Publication

02/07/2025

CVE-2024-5567 Moyenne · 6,4
Betheme

Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.5 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-27.5.5

Correctif

27.5.6

Publication

12/09/2024

CVE-2024-3998 Moyenne · 6,4
Betheme

Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-27.5.6

Correctif

Non indiqué

Publication

29/08/2024

CVE-2023-47770 Moyenne · 6,3
Betheme

Betheme <= 27.1.1 – Missing Authorization

The Betheme theme for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 27.1.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-27.1.1

Correctif

27.1.2

Publication

14/11/2023

CVE-2023-29101 Moyenne · 6,1
Betheme

Betheme <= 26.7.5 – Reflected Cross-Site Scripting

The Betheme theme for WordPress is vulnerable to Reflected Cross-Site Scripting on shop pages in versions up to, and including, 26.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-26.7.5

Correctif

26.8

Publication

13/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités