WordPress security by component
XStore Core
Plugin description
XStore Core is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
et-core-pluginLatest vulnerability
CVE-2026-25306: XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.4.
| Safe version |
|
||
|---|---|---|---|
| Mar 25, 2026 |
CVE-2026-25306
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.4.
|
5.6.5 |
CVE7.1
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25307
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 30, 2025 |
CVE-2025-64190
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64189
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 09, 2024 |
CVE-2024-33555
XStore Core: A security weakness
XStore Core is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.1
NVD8.8
|
| Jun 04, 2024 |
CVE-2024-33557
XStore Core: Filesystem traversal
XStore Core is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| May 17, 2024 |
CVE-2024-33552
XStore Core: Privilege escalation or authentication bypass
XStore Core is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| May 17, 2024 |
CVE-2024-33556
XStore Core: Dangerous file upload
XStore Core is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.2
NVD9.8
|
| Apr 29, 2024 |
CVE-2024-33558
XStore Core: A security weakness
XStore Core is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Apr 29, 2024 |
CVE-2024-33553
XStore Core: Code execution
XStore Core is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.0
NVD9.8
|
| Apr 29, 2024 |
CVE-2024-33554
XStore Core: Cross-site scripting
XStore Core is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Apr 29, 2024 |
CVE-2024-33551
XStore Core: SQL injection
XStore Core is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|