Vendors8THEMExstore_coreall versions
Vulnerabilities

8THEME XStore Core

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-33551
WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerability
Published 2024-04-29 · Modified
9.8EPSS 0.006
CVE-2024-33556
WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability
Published 2024-05-17 · Analyzed
9.8EPSS 0.006
CVE-2024-33553
WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability
Published 2024-04-29 · Modified
9.8EPSS 0.006
CVE-2024-33552
WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability
Published 2024-05-17 · Analyzed
9.8EPSS 0.006
CVE-2024-33557
WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-33555
WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability
Published 2024-06-09 · Modified
8.8EPSS 0.004
CVE-2024-33554
WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-04-29 · Modified
7.1EPSS 0.004
CVE-2024-33558
WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability
Published 2024-04-29 · Modified
6.5EPSS 0.004