CVE-2024-33557: WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33557?
CVE-2024-33557 has been assessed with a high severity rating due to its ability to allow PHP Local File Inclusion, which can lead to arbitrary code execution.
How do I fix CVE-2024-33557?
To mitigate CVE-2024-33557, update the XStore Core plugin to version 5.3.9 or later, where the vulnerability has been addressed.
Which versions of the XStore Core are affected by CVE-2024-33557?
CVE-2024-33557 affects all versions of XStore Core from n/a through 5.3.8.
What type of vulnerability is CVE-2024-33557?
CVE-2024-33557 is classified as a Path Traversal vulnerability that enables improper limitation of a pathname to a restricted directory.
Can CVE-2024-33557 allow unauthorized access?
Yes, CVE-2024-33557 can potentially allow attackers to gain unauthorized access to sensitive files on the server through Local File Inclusion.