CVE-2024-33564: WordPress XStore theme <= 9.3.8 - Arbitrary Option Update vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
Affected Software
1 affected component
8theme Xstore Wordpress<9.3.9
Remediation
Information
Update to 9.3.9 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33564?
CVE-2024-33564 is considered a high severity vulnerability due to the missing authorization issue that can lead to unauthorized actions.
2
How do I fix CVE-2024-33564?
To fix CVE-2024-33564, update your XStore theme to version 9.3.9 or later, where the vulnerability is addressed.
3
Who is affected by CVE-2024-33564?
CVE-2024-33564 affects users of the 8theme XStore theme from any version up to 9.3.8.
4
What type of vulnerability is CVE-2024-33564?
CVE-2024-33564 is classified as a Missing Authorization vulnerability.
5
Is there a workaround for CVE-2024-33564?
There are no recommended workarounds for CVE-2024-33564; the best action is to update the theme to the latest version.