CVE-2026-6262 | MuffinGroup Betheme Plugin up to 28.4 on WordPress upload_icons path traversal
A vulnerability has been found in MuffinGroup Betheme Plugin up to 28.4 on WordPress and classified as critical. The affected element is the function upload_icons. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-6262. The attack is possible to be carried out remotely. No exploit exists.