8theme Vulnerabilities and Affected Products
Vulnerabilities associated with XStore Core.
Products
Clear product- XStore13 vulnerabilities
- XStore Core12 vulnerabilities
- xstore_core4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-25306HIGH | WordPress XStore Core plugin <= 5.6.4 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4. CWE-79Mar 25, 2026 | CVSS7.1v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25307MEDIUM | WordPress XStore Core plugin < 5.7 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7. CWE-79Feb 19, 2026 | CVSS6.5v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64190MEDIUM | WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6. CWE-79Dec 30, 2025 | CVSS6.5v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64189HIGH | WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6. CWE-79Dec 18, 2025 | CVSS7.1v3.1 | EPSS0.191% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33555HIGH | WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. CWE-862Jun 9, 2024 | CVSS8.1v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33557HIGH | WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8. CWE-22Jun 4, 2024 | CVSS8.5v3.1 | EPSS0.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33552CRITICAL | WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerabilityImproper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8. CWE-269May 17, 2024 | CVSS9.8v3.1 | EPSS0.571% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33556HIGH | WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. CWE-434May 17, 2024 | CVSS8.2v3.1 | EPSS0.583% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33558MEDIUM | WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerabilityMissing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5. CWE-862Apr 29, 2024 | CVSS6.5v3.1 | EPSS0.435% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33553CRITICAL | WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5. CWE-502Apr 29, 2024 | CVSS9.0v3.1 | EPSS0.576% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33551CRITICAL | WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5. CWE-89Apr 29, 2024 | CVSS9.3v3.1 | EPSS0.614% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33554HIGH | WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5. CWE-79Apr 29, 2024 | CVSS7.1v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |