First published: Fri May 17 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
8theme XStore | >=5.3.8 | |
WordPress XStore Core | <=5.3.8 |
Update to 5.3.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33556 is classified as a high severity vulnerability due to the potential for arbitrary file uploads that could lead to code execution.
To fix CVE-2024-33556, update the XStore Core plugin to version 5.3.9 or later, which addresses this vulnerability.
CVE-2024-33556 can allow attackers to upload malicious files, potentially compromising the server and exposing sensitive data.
CVE-2024-33556 affects all versions of XStore Core up to and including version 5.3.8.
CVE-2024-33556 is specific to the XStore Core plugin used in WordPress.