CVE-2024-33556: WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability
Published May 17, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
Affected Software
3 affected components
8theme Xstore Core Wordpress<5.3.9
8theme XStore Core>=5.3.8
WordPress XStore Core<=5.3.8
Remediation
Information
Update to 5.3.9 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:12 AM
Data Sourced
via MITRE·06:12 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33556?
CVE-2024-33556 is classified as a high severity vulnerability due to the potential for arbitrary file uploads that could lead to code execution.
2
How do I fix CVE-2024-33556?
To fix CVE-2024-33556, update the XStore Core plugin to version 5.3.9 or later, which addresses this vulnerability.
3
What are the impacts of CVE-2024-33556?
CVE-2024-33556 can allow attackers to upload malicious files, potentially compromising the server and exposing sensitive data.
4
Which versions of XStore Core are affected by CVE-2024-33556?
CVE-2024-33556 affects all versions of XStore Core up to and including version 5.3.8.
5
Is CVE-2024-33556 specific to any platforms?
CVE-2024-33556 is specific to the XStore Core plugin used in WordPress.