Betheme 28.4 vulnerability
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4.

The official explanation;
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload flow.
What this means;
Anyone with “author” level access could, in theory, upload a .zip file containing harmful code into the website. A bad actor could maliciously upload some PHP into the website, gaining the ability to execute code, potentially causing loss of content, data theft, or even taking the website offline entirely.
Next steps;
Update Betheme to the latest secure version. This issue was patched in 28.4.1, so anything after this should be secure again.
Unfortunately, this isn’t the first time Betheme has faced scrutiny with regard to security compliance. There was a PHP injection issue discovered in 2024, as well as several cross site scripting issues discovered throughout 2025.
At GeoBrand we avoid using themes for many reasons, security being one of them. If your site is currently running Betheme, even a currently secure version, do get in touch to see if we can help get your site permanently secure.
© GeoBrand. All rights reserved.