← WordPress Vulnerabilities
WordPress security by component

XStore Core

XStore Core is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: et-core-plugin

CVE-2026-25306: XStore Core: Cross-site scripting

XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.4.

PublishedMar 25, 2026
Known safe version5.6.5
Safe version
Mar 25, 2026 CVE-2026-25306
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.4.
5.6.5
CVE7.1
NVDPending
Feb 19, 2026 CVE-2026-25307
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 30, 2025 CVE-2025-64190
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-64189
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 09, 2024 CVE-2024-33555
XStore Core: A security weakness
XStore Core is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVD8.8
Jun 04, 2024 CVE-2024-33557
XStore Core: Filesystem traversal
XStore Core is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.5
NVD8.8
May 17, 2024 CVE-2024-33552
XStore Core: Privilege escalation or authentication bypass
XStore Core is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
May 17, 2024 CVE-2024-33556
XStore Core: Dangerous file upload
XStore Core is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.2
NVD9.8
Apr 29, 2024 CVE-2024-33558
XStore Core: A security weakness
XStore Core is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Apr 29, 2024 CVE-2024-33553
XStore Core: Code execution
XStore Core is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.0
NVD9.8
Apr 29, 2024 CVE-2024-33554
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 29, 2024 CVE-2024-33551
XStore Core: SQL injection
XStore Core is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8