CVE-2024-33562: WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.
Affected Software
1 affected component
8theme XStore<=9.3.5
Event History
Apr 29, 2024
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33562?
CVE-2024-33562 has been classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-33562?
To fix CVE-2024-33562, upgrade the 8theme XStore theme to version 9.3.6 or later.
3
What is the impact of CVE-2024-33562?
CVE-2024-33562 can allow attackers to execute arbitrary JavaScript in the context of the victim's browser.
4
Is my version of XStore affected by CVE-2024-33562?
Yes, all versions of 8theme XStore theme up to and including 9.3.5 are affected by CVE-2024-33562.
5
How can I detect CVE-2024-33562 on my website?
You can detect CVE-2024-33562 by scanning your site for vulnerable versions of the XStore theme using automated security tools.