CVE-2024-33554: WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.
Affected Software
3 affected components
8theme Xstore Core Wordpress<5.3.9
8theme XStore Core<=5.3.5
WordPress XStore Core<=5.3.5
Event History
Apr 29, 2024
CVE Published
via MITRE·05:16 AM
Data Sourced
via MITRE·05:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33554?
CVE-2024-33554 is classified as a medium severity Reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-33554?
To fix CVE-2024-33554, upgrade the XStore Core plugin to a version higher than 5.3.5.
3
Who is affected by CVE-2024-33554?
CVE-2024-33554 affects users of the XStore Core plugin for WordPress up to version 5.3.5.
4
What type of vulnerability is CVE-2024-33554?
CVE-2024-33554 is an Improper Neutralization of Input During Web Page Generation vulnerability, leading to Cross-site Scripting (XSS).
5
Can CVE-2024-33554 be exploited remotely?
Yes, CVE-2024-33554 can be exploited remotely by sending specially crafted requests to the vulnerable XStore Core.