CVE-2024-33561: WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
Affected Software
1 affected component
8theme Xstore Wordpress<9.3.9
Remediation
Information
Update to 9.3.9 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33561?
CVE-2024-33561 is classified as a medium severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-33561?
To fix CVE-2024-33561, update to XStore version 9.3.9 or later.
3
What vulnerabilities does CVE-2024-33561 affect?
CVE-2024-33561 affects the 8theme XStore theme from versions n/a through 9.3.8.
4
What is the nature of the vulnerability in CVE-2024-33561?
CVE-2024-33561 is a Missing Authorization vulnerability that could allow unauthorized users to access restricted functionality.
5
Who is impacted by CVE-2024-33561?
Any users of the 8theme XStore theme versions up to 9.3.8 are impacted by CVE-2024-33561.