CVE-2024-33563: WordPress XStore theme <= 9.3.8 - Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
Affected Software
1 affected component
8theme Xstore Wordpress<9.3.9
Remediation
Information
Update to 9.3.9 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33563?
The severity of CVE-2024-33563 is classified as a high risk due to its potential for unauthorized access.
2
How do I fix CVE-2024-33563?
To fix CVE-2024-33563, upgrade the 8theme XStore plugin to version 9.3.9 or later.
3
What systems are affected by CVE-2024-33563?
CVE-2024-33563 affects all versions of 8theme XStore from n/a through 9.3.8.
4
Is CVE-2024-33563 an isolated vulnerability?
CVE-2024-33563 is not isolated; it represents a broader issue of missing authorization in the XStore theme.
5
What kind of exploit can occur due to CVE-2024-33563?
Exploitation of CVE-2024-33563 can lead to unauthorized actions being performed on behalf of legitimate users.