CVE-2026-6262: Betheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the uploadicons() function workflow using a user-controlled upload path (mfn-icon-upload) in a filesystem move operation without constraining it to the uploads directory. This makes it possible for authenticated attackers, with contributor-level access and above, to move/delete arbitrary local files via path traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6262?
CVE-2026-6262 is considered a critical vulnerability due to its potential for arbitrary file deletion.
How do I fix CVE-2026-6262?
To fix CVE-2026-6262, update the Betheme theme to version 28.5 or later immediately.
Who is affected by CVE-2026-6262?
Users of Betheme versions up to and including 28.4 are affected by CVE-2026-6262.
What type of vulnerability is CVE-2026-6262?
CVE-2026-6262 is classified as an Authenticated Arbitrary File Deletion vulnerability.
What can an attacker do with CVE-2026-6262?
An attacker with Contributor+ access can exploit CVE-2026-6262 to delete arbitrary files on the server.