XStore < 9.7.3 - Unauthenticated SQL Injection
high
The XStore theme for WordPress is vulnerable to SQL Injection in versions up to 9.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer...
- CVSS:
- 7.5
- Affected:
- up to 9.7.3
- Fixed in:
- 9.7.3
- Disclosed:
- Jun 11, 2026
CVE-2026-3326 on NVD →
XStore [xstore] <= 9.6.4 (unfixed)
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.
- Affected:
- up to 9.6.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25006 on NVD →
XStore [xstore] <= 9.6.4 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4.
- Affected:
- up to 9.6.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25305 on NVD →
XStore <= 9.6.4 - Unauthenticated Arbitrary Shortcode Execution
medium
The The XStore theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.6.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to exec...
- CVSS:
- 6.5
- Affected:
- up to 9.6.4
- Fixed in:
- 9.6.5
- Disclosed:
- Jan 18, 2026
CVE-2026-25006 on NVD →
XStore <= 9.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The XStore theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 9.6.4
- Fixed in:
- 9.6.5
- Disclosed:
- Jan 18, 2026
CVE-2026-25305 on NVD →
XStore [xstore] < 9.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1.
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.1
- Disclosed:
- Dec 18, 2025
CVE-2025-64191 on NVD →
XStore [xstore] < 9.6
unknown
[en] Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6.
- Affected:
- up to 9.6
- Fixed in:
- 9.6
- Disclosed:
- Dec 18, 2025
CVE-2025-64192 on NVD →
XStore [xstore] < 9.6.1
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1.
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.1
- Disclosed:
- Dec 18, 2025
CVE-2025-64193 on NVD →
XStore [xstore] < 9.6
unknown
[en] The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, a...
- Affected:
- up to 9.6
- Fixed in:
- 9.6
- Disclosed:
- Oct 15, 2025
CVE-2025-11746 on NVD →
XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion
high
The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowi...
- CVSS:
- 8.8
- Affected:
- up to 9.5.4
- Fixed in:
- 9.6
- Disclosed:
- Oct 14, 2025
CVE-2025-11746 on NVD →
XStore < 9.6 - Unauthenticated Arbitrary Shortcode Execution
medium
The The XStore theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and excluding, 9.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execut...
- CVSS:
- 6.5
- Affected:
- up to 9.6
- Fixed in:
- 9.6
- Disclosed:
- Sep 26, 2025
CVE-2025-60100 on NVD →
XStore [xstore] <= 9.5.3 (unfixed)
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3.
- Affected:
- up to 9.5.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 26, 2025
CVE-2025-60100 on NVD →
XStore < 9.6.1 - Authenticated (Subscriber+) Local File Inclusion
high
The XStore theme for WordPress is vulnerable to Local File Inclusion in versions up to 9.6.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypas...
- CVSS:
- 7.5
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.1
- Disclosed:
- Sep 10, 2025
CVE-2025-64193 on NVD →
XStore < 9.6.1 - Reflected Cross-Site Scripting
medium
The XStore theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 9.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into perform...
- CVSS:
- 6.1
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.1
- Disclosed:
- Sep 10, 2025
CVE-2025-64191 on NVD →
XStore < 9.6 - Missing Authorization
medium
The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 9.6 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 9.6
- Fixed in:
- 9.6
- Disclosed:
- Sep 10, 2025
CVE-2025-64192 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2024
CVE-2024-33561 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2024
CVE-2024-33564 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2024
CVE-2024-33563 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a through 9.3.8.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2024
CVE-2024-33560 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2024
CVE-2024-33562 on NVD →
XStore [xstore] <= 9.3.5 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
- Affected:
- up to 9.3.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2024
CVE-2024-33559 on NVD →
XStore <= 9.3.8 - Unauthenticated SQL Injection
critical
The XStore theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.3.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alre...
- CVSS:
- 10
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33559 on NVD →
XStore <= 9.3.8 - Unauthenticated Local File Inclusion
critical
The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.3.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...
- CVSS:
- 9.8
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33560 on NVD →
XStore <= 9.3.8 - Authenticated (Subscriber+) Arbitrary Options Update
high
The XStore theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and including, 9.3.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options which can be used to achi...
- CVSS:
- 8.8
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33564 on NVD →
XStore <= 9.3.8 - Reflected Cross-Site Scripting
medium
The XStore theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a u...
- CVSS:
- 6.1
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33562 on NVD →
XStore <= 9.3.8 - Missing Authorization
medium
The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.3.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33561 on NVD →
XStore <= 9.3.8 - Missing Authorization
medium
The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.3.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 9.3.8
- Fixed in:
- 9.3.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33563 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database