The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
We have discovered 58,540 live websites that are affected by CVE-2024-2694.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 58,540 live websites (64% of BeTheme install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 319 versions ( 91% of all versions) |
| 12,309 websites | |
| 7,298 websites | |
| 4,078 websites | |
| 3,067 websites | |
| 2,947 websites | |
| 2,005 websites | |
| 1,914 websites | |
| 1,889 websites | |
| 1,706 websites | |
| 1,408 websites |
| .com | 21,089 websites |
| .de | 4,359 websites |
| .it | 3,000 websites |
| .com.br | 2,983 websites |
| .org | 1,798 websites |
| .nl | 1,511 websites |
| .fr | 1,490 websites |
| .pl | 1,462 websites |
| .ru | 1,126 websites |
| .co.uk | 1,123 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.nl | *,*** | ||
| ******.fr | **,*** | ||
| ****************************.com | **,*** | ||
| **********.com | **,*** | ||
| ************.com | **,*** | ||
| **********.com | **,*** | ||
| ***************.com | **,*** | ||
| ***********.de | **,*** | ||
| ***********.com | ***,*** | ||
| *******.**.ke | ***,*** |
FAQ