First published: Tue Jun 04 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
8theme XStore | >=5.3.8 | |
WordPress XStore Core | <=5.3.8 |
Update to 5.3.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33557 has been assessed with a high severity rating due to its ability to allow PHP Local File Inclusion, which can lead to arbitrary code execution.
To mitigate CVE-2024-33557, update the XStore Core plugin to version 5.3.9 or later, where the vulnerability has been addressed.
CVE-2024-33557 affects all versions of XStore Core from n/a through 5.3.8.
CVE-2024-33557 is classified as a Path Traversal vulnerability that enables improper limitation of a pathname to a restricted directory.
Yes, CVE-2024-33557 can potentially allow attackers to gain unauthorized access to sensitive files on the server through Local File Inclusion.