Record summary

CVE-2026-3326 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Xstore

Default status: unaffected

CVE ListBefore 9.7.3affected

Nuclei templates

1
ProjectDiscoveryHIGHXStore Theme < 9.7.3 - SQL InjectionCVSS 8.6

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Impact

Unauthenticated attackers can extract arbitrary data from the WordPress database, including credentials, session tokens, and WooCommerce customer records.

Remediation

Update XStore theme to version 9.7.3 or later.

WeaknessesCWE-89
AuthorsVixianSchool
Template tagscvecve2026wordpresswpwp-themesqlixstore
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Source: ProjectDiscovery

References

2