CVE-2024-33552: WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
Affected Software
3 affected components
8theme Xstore Core Wordpress<5.3.9
8theme XStore Core>=5.3.8
WordPress XStore Core<=5.3.8
Remediation
Information
Update to 5.3.9 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33552?
CVE-2024-33552 has been classified with a severity level indicating a significant risk due to its potential for privilege escalation.
2
How do I fix CVE-2024-33552?
To fix CVE-2024-33552, you should update the XStore Core plugin to the latest version beyond 5.3.8.
3
What software is affected by CVE-2024-33552?
CVE-2024-33552 affects versions of 8theme XStore Core from n/a to 5.3.8.
4
What type of vulnerability is CVE-2024-33552?
CVE-2024-33552 is an improper privilege management vulnerability that allows for privilege escalation.
5
Who is the vendor of the affected software in CVE-2024-33552?
The vendor of the affected software related to CVE-2024-33552 is 8theme.