CVE-2024-33555: WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
Affected Software
1 affected component
8theme Xstore Core Wordpress<5.3.9
Remediation
Information
Update to 5.3.9 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33555?
CVE-2024-33555 is classified as a Missing Authorization vulnerability, which can lead to unauthorized access to sensitive functionality.
2
How do I fix CVE-2024-33555?
To fix CVE-2024-33555, upgrade the XStore Core plugin to version 5.3.9 or later.
3
Which versions of XStore Core are affected by CVE-2024-33555?
XStore Core versions prior to 5.3.9 are affected by CVE-2024-33555.
4
What impacts does CVE-2024-33555 have on WordPress sites?
CVE-2024-33555 can potentially allow attackers to exploit broken access controls, leading to unauthorized actions on WordPress sites.
5
Who is the vendor for XStore Core affected by CVE-2024-33555?
The vendor for XStore Core is 8theme.