CVE-2025-60100: WordPress XStore theme < 9.6 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through < 9.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60100?
CVE-2025-60100 is considered a critical severity vulnerability due to its potential for code injection through cross-site scripting (XSS).
How do I fix CVE-2025-60100?
To fix CVE-2025-60100, update the 8theme XStore theme to version 9.5.4 or later to mitigate the vulnerability.
Which versions of XStore are affected by CVE-2025-60100?
CVE-2025-60100 affects all versions of the XStore theme from n/a to 9.5.3.
What type of vulnerability is CVE-2025-60100?
CVE-2025-60100 is an improper neutralization of script-related HTML tags, classified as a basic cross-site scripting (XSS) vulnerability.
Can CVE-2025-60100 affect WordPress websites?
Yes, CVE-2025-60100 can affect WordPress websites that use the XStore theme versions up to 9.5.3.