CVE-2024-33559: WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
Published Apr 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
Credit
Abdualhadi khalifa
Affected Software
1 affected component
8theme XStore WordPress theme<=9.3.5, =9.3.8
Event History
Apr 29, 2024
CVE Published
via MITRE·06:04 AM
Data Sourced
via MITRE·06:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
May 19, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-33559?
CVE-2024-33559 has a high severity rating due to its potential to allow unauthorized SQL Injection attacks.
2
How do I fix CVE-2024-33559?
To fix CVE-2024-33559, update the XStore theme to version 9.3.6 or higher.
3
What are the potential impacts of CVE-2024-33559?
CVE-2024-33559 can lead to unauthorized access to sensitive database information and manipulation of data.
4
Which versions of XStore are affected by CVE-2024-33559?
CVE-2024-33559 affects XStore versions up to and including 9.3.5.
5
Is CVE-2024-33559 exploitable without authentication?
Yes, CVE-2024-33559 allows for unauthenticated SQL Injection, making it easier for attackers to exploit.