First published: Tue Jun 04 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a through 9.3.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
XStore | ||
WordPress XStore | <=9.3.8 |
Update to 9.3.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33560 is considered a critical vulnerability due to its potential for PHP Local File Inclusion, which can lead to unauthorized file access on affected systems.
To fix CVE-2024-33560, update the XStore theme to version 9.3.9 or later, which addresses this security issue.
CVE-2024-33560 affects XStore theme versions up to and including 9.3.8.
Not patching CVE-2024-33560 may allow attackers to exploit the vulnerability, potentially leading to unauthorized access to sensitive files on the server.
Yes, CVE-2024-33560 specifically affects the XStore theme used in WordPress.