Junglewise Threat Intelligence

CVE-2026-6178: Betheme stored cross-site scripting in icon_box_2 shortcode

CVE-2026-6178 · Severity: medium · CVSS 6.4 · Published 2026-08-26

Executive brief

The Betheme WordPress theme contains a vulnerability in its icon_box_2 shortcode that allows authenticated users with contributor access or higher to inject malicious scripts into pages. When other users visit these compromised pages, the injected scripts execute in their browsers, potentially stealing session data, redirecting to malicious sites, or performing unauthorized actions on their behalf.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the theme's icon_box_2 shortcode caused by insufficient input sanitization and output escaping of user-supplied shortcode attributes. An authenticated attacker with contributor-level access can craft a malicious shortcode with unescaped attributes that persists in the WordPress database. The stored payload executes in the browser context of any user who views the affected page, allowing script injection without requiring additional user interaction. Patches are available in versions after 28.4.

Affected products

  • Muffin Group Betheme up to 28.4

Timeline

  • 2026-08-26: disclosed

References