Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-65548: Betheme <= 28.4.2: Unauthenticated Remote Code Execution

CVE-2026-65548 · published 29 days ago
Summary

Betheme theme for WordPress has a vulnerability that allows attackers to run malicious code on a website. This could lead to unauthorized access, data theft, or even website takeover. Update Betheme to version 28.4.3 or later to fix this issue.

Original advisory text
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen6 Aug 2026
Sources
Monitor software like this
Free during beta