8theme XStore Security Update Advisory

Overview

 

We have released an update to address a vulnerability in the 8theme XStore. users of affected versions are advised to update to the latest version.

 

Affected Products

 

8theme XStore version: 9.3.8 or below (include)

 

Resolved Vulnerabilities

 

SQL Injection vulnerability due to improper neutralization of special elements in 8theme XStore (CVE-2024-33559)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

8theme XStore version 9.3.9

 

Referenced Sites

 

[1] CVE-2024-33559 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-33559

[2] WordPress XStore Theme <= 9.3.8 is vulnerable to SQL Injection

https://patchstack.com/database/vulnerability/xstore/wordpress-xstore-theme-9-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve