CVE-2023-39998

WordPress BeTheme theme <= 27.1.1 - Author+ Broken Access Control vulnerability

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.


We have discovered 68,577 live websites that are affected by CVE-2023-39998.

Test my site




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Domains68,577 live websites (61.89% of BeTheme install base)
Vulnerable Versions
  • from 0 through 27.1.1
Vulnerable Versions Count543 versions ( 89.31% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 19, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-39998 usage by Country

United States19,923 websites



Germany9,431 websites
France4,103 websites
Brazil2,887 websites
Italy2,454 websites
Poland2,320 websites
GB2,013 websites
Spain1,912 websites
Netherlands1,722 websites
Russia1,636 websites

CVE-2023-39998 usage by TLD

.com25,613 websites
.de4,553 websites
.com.br3,705 websites
.fr2,605 websites
.it2,140 websites
.org2,017 websites
.pl1,840 websites
.nl1,695 websites
.ru1,320 websites
.co.uk1,291 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-39998

Top websites that are affected by CVE-2023-39998. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.nl United States*,***
*****************.com United States**,***
******.fr France**,***
**********.com United States**,***
**********.com United States**,***
***********.de Germany**,***
***********.com Singapore***,***
*******.**.ke Kenya***,***
*******.de Germany***,***
*******.com United States***,***
See full domain list

FAQ

CVE-2023-39998 is Missing Authorization in BeTheme
A total of 68,577 websites have been identified as vulnerable to CVE-2023-39998, discovered through global website indexing conducted by WebTechSurvey.
BeTheme is susceptible to CVE-2023-39998 vulnerability.
BeTheme versions before, and including, 27.1.1 are vulnerable to CVE-2023-39998.