Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

XStore — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in XStore, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of vulnerability data for the XStore WordPress theme, focusing on common weakness categories and specific security tags associated with this vendor. It collects a wide variety of known security issues, including cross-site scripting, SQL injection, authentication bypass, and authorization flaws that have been publicly disclosed or tracked within the last five years. The data reflects both critical severity ratings and less severe informational findings to ensure a holistic view of the product's security posture over time. By visiting this resource, users can effectively track vendor advisories from the XStore development team to stay informed about official patches and mitigation strategies. Visitors are also able to understand a specific weakness class by examining how different vulnerabilities manifest within this particular software environment, providing context on exploitation methods and impact. Additionally, the page allows users to look up a product's vulnerability history to identify patterns, recurring issues, or the frequency of updates, which is essential for maintaining the security integrity of any website using this theme. This information is presented without bias or promotional language, serving strictly as a technical reference for developers, security analysts, and administrators. The goal is to facilitate better decision-making regarding patch management and risk assessment by providing clear, structured access to historical and current security incidents related to XStore.

Vendor: 8theme

CVE IDTitleCVSSSeverityPublished
CVE-2026-3326 XStore < 9.7.3 - Unauthenticated SQLi --2026-06-10
CVE-2026-25305 WordPress XStore theme <= 9.6.4 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-02-19
CVE-2026-25006 WordPress XStore theme <= 9.6.4 - Arbitrary Shortcode Execution vulnerability CWE-80 5.3 Medium2026-02-19
CVE-2025-64193 WordPress XStore theme < 9.6.1 - Local File Inclusion vulnerability CWE-98 7.5 High2025-12-18
CVE-2025-64192 WordPress XStore theme < 9.6 - Broken Access Control vulnerability CWE-862 6.3 Medium2025-12-18
CVE-2025-64191 WordPress XStore theme < 9.6.1 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-12-18
CVE-2025-11746 XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion CWE-22 8.8 High2025-10-15
CVE-2025-60100 WordPress XStore theme < 9.6 - Content Injection vulnerability CWE-80 5.3 Medium2025-09-26
CVE-2024-33561 WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability CWE-862 7.5 High2024-06-09
CVE-2024-33563 WordPress XStore theme <= 9.3.8 - Broken Access Control vulnerability CWE-862 7.6 High2024-06-09
CVE-2024-33564 WordPress XStore theme <= 9.3.8 - Arbitrary Option Update vulnerability CWE-862 8.8 High2024-06-09
CVE-2024-33560 WordPress XStore theme <= 9.3.8 - Unauthenticated Local File Inclusion vulnerability CWE-22 9.0 Critical2024-06-04
CVE-2024-33559 WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability CWE-89 9.3 Critical2024-04-29
CVE-2024-33562 WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-04-29

All 14 known CVE vulnerabilities affecting XStore with full Chinese analysis, references, and POCs where available.