Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

XStore Core — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in XStore Core, with AI-generated Chinese analysis, references, and POCs.

XStore Core is a widely used e-commerce platform developed by 7th Avenue, and this page aggregates known security weaknesses associated with its software components. The content focuses on Common Weakness Enumerations (CWE) and associated CVE records that have been publicly disclosed or tracked for this specific product line. This collection covers a broad time range, starting from early initial releases up to recent security patches, ensuring that both legacy and current vulnerabilities are accessible for review. Visitors to this page can efficiently track vendor advisories issued by 7th Avenue as they address identified flaws in their software ecosystem. Users can also gain a deeper understanding of specific weakness classes that frequently impact XStore Core, such as SQL injection or cross-site scripting, by examining how these abstract vulnerabilities manifest in real-world scenarios within this environment. Furthermore, the page serves as a historical record, allowing security professionals and administrators to look up the vulnerability history of the product. This includes viewing the evolution of security issues over time, which aids in assessing long-term risk profiles and prioritizing remediation efforts. By centralizing this data, the page provides a comprehensive overview of the security landscape for XStore Core, facilitating better decision-making for system hardening and compliance audits without relying on fragmented external sources.

Vendor: 8theme

CVE ID Title CVSS Severity Published
CVE-2026-25306 WordPress XStore Core plugin <= 5.6.4 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-03-25
CVE-2026-25307 WordPress XStore Core plugin < 5.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-02-19
CVE-2025-64190 WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-12-30
CVE-2025-64189 WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-12-18
CVE-2024-33555 WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability CWE-862 8.1 High 2024-06-09
CVE-2024-33557 WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability CWE-22 8.5 High 2024-06-04
CVE-2024-33552 WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability CWE-269 9.8 Critical 2024-05-17
CVE-2024-33556 WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability CWE-434 8.2 High 2024-05-17
CVE-2024-33558 WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability CWE-862 6.5 Medium 2024-04-29
CVE-2024-33553 WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability CWE-502 9.0 Critical 2024-04-29
CVE-2024-33551 WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerability CWE-89 9.3 Critical 2024-04-29
CVE-2024-33554 WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-04-29

All 12 known CVE vulnerabilities affecting XStore Core with full Chinese analysis, references, and POCs where available.