Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

XStore — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in XStore, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for XStore, a widely used e-commerce solution, focusing on Common Weakness Enumerations (CWE) and vendor-reported advisories. It compiles historical security incidents ranging from critical remote code execution flaws to lower-severity cross-site scripting and information disclosure issues. The collection spans multiple major releases of the software, capturing the evolution of security patches and the recurring nature of specific defect classes over time. Readers can utilize this resource to track XStore vendor advisories and monitor the pace of remediation efforts. It provides a structured view to understand specific weakness classes within the context of web application frameworks, highlighting how common architectural flaws manifest in commercial products. Users can also look up the complete vulnerability history of XStore to assess risk exposure across different versions. This aggregation serves as a neutral reference point for security professionals, developers, and auditors who need to evaluate the integrity of the software stack without bias. By presenting data in a consolidated format, the page facilitates comparative analysis against industry standards and helps identify trends in patch management. The information is organized to support due diligence in software supply chain security, allowing stakeholders to make informed decisions about upgrade paths and mitigation strategies. This document does not include specific CVE identifiers but focuses on the broader landscape of identified defects and their resolutions.

Vendor: 8theme

CVE ID Title CVSS Severity Published
CVE-2026-3326 XStore < 9.7.3 - Unauthenticated SQLi - - 2026-06-10
CVE-2026-25305 WordPress XStore theme <= 9.6.4 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-02-19
CVE-2026-25006 WordPress XStore theme <= 9.6.4 - Arbitrary Shortcode Execution vulnerability CWE-80 5.3 Medium 2026-02-19
CVE-2025-64193 WordPress XStore theme < 9.6.1 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-12-18
CVE-2025-64192 WordPress XStore theme < 9.6 - Broken Access Control vulnerability CWE-862 6.3 Medium 2025-12-18
CVE-2025-64191 WordPress XStore theme < 9.6.1 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-12-18
CVE-2025-11746 XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion CWE-22 8.8 High 2025-10-15
CVE-2025-60100 WordPress XStore theme < 9.6 - Content Injection vulnerability CWE-80 5.3 Medium 2025-09-26
CVE-2024-33561 WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability CWE-862 7.5 High 2024-06-09
CVE-2024-33563 WordPress XStore theme <= 9.3.8 - Broken Access Control vulnerability CWE-862 7.6 High 2024-06-09
CVE-2024-33564 WordPress XStore theme <= 9.3.8 - Arbitrary Option Update vulnerability CWE-862 8.8 High 2024-06-09
CVE-2024-33560 WordPress XStore theme <= 9.3.8 - Unauthenticated Local File Inclusion vulnerability CWE-22 9.0 Critical 2024-06-04
CVE-2024-33559 WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability CWE-89 9.3 Critical 2024-04-29
CVE-2024-33562 WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-04-29

All 14 known CVE vulnerabilities affecting XStore with full Chinese analysis, references, and POCs where available.