nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6262 CVE-2026-6262
MEDIUM
Betheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'
Record summary
CVE-2026-6262 has a selected CVSS score of 6.5 (medium).
Description
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path (`mfn-icon-upload`) in a filesystem move operation without constraining it to the uploads directory. This makes it possible for authenticated attackers, with contributor-level access and above, to move/delete arbitrary local files via path traversal.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BethemeBrowse MuffinGroup / BethemeDefault status: unaffected | CVE List | Through 28.4 | affected |
References
3support.muffingroup.com
https://support.muffingroup.com/changelog wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3486f114-5625-4751-a25e-2c5ab7b15b38?source=cve