First published: Mon Apr 29 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
XStore | <=9.3.5 | |
WordPress XStore | <=9.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33562 has been classified as a reflected Cross-site Scripting (XSS) vulnerability.
To fix CVE-2024-33562, upgrade the 8theme XStore theme to version 9.3.6 or later.
CVE-2024-33562 can allow attackers to execute arbitrary JavaScript in the context of the victim's browser.
Yes, all versions of 8theme XStore theme up to and including 9.3.5 are affected by CVE-2024-33562.
You can detect CVE-2024-33562 by scanning your site for vulnerable versions of the XStore theme using automated security tools.