CVE-2024-33553: WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability
Published Apr 29, 2024
·Updated
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
Affected Software
3 affected components
8theme Xstore Core Wordpress<5.3.9
8theme XStore Core<=5.3.5
WordPress XStore Core plugin<=5.3.5
Event History
Apr 29, 2024
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33553?
CVE-2024-33553 is classified as a high severity vulnerability due to the potential for remote code execution through deserialization of untrusted data.
2
How do I fix CVE-2024-33553?
To fix CVE-2024-33553, upgrade the 8theme XStore Core or WordPress XStore Core plugin to version 5.3.6 or later.
3
What versions are affected by CVE-2024-33553?
CVE-2024-33553 affects all versions of 8theme XStore Core and WordPress XStore Core plugin up to and including version 5.3.5.
4
What type of vulnerability is CVE-2024-33553?
CVE-2024-33553 is a deserialization of untrusted data vulnerability, which can lead to remote code execution.
5
Who is impacted by CVE-2024-33553?
Users of 8theme XStore Core and WordPress XStore Core plugin versions up to 5.3.5 are at risk from CVE-2024-33553.