CVE-2025-64190: WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme.Com XStore Core allows DOM-Based XSS.This issue affects XStore Core: from n/a before 5.6.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64190?
CVE-2025-64190 is classified as a medium severity Cross-site Scripting (XSS) vulnerability affecting versions of 8theme.Com XStore Core prior to 5.6.
How do I fix CVE-2025-64190?
To fix CVE-2025-64190, update your 8theme.Com XStore Core plugin to version 5.6 or later.
What systems are affected by CVE-2025-64190?
CVE-2025-64190 affects 8theme.Com XStore Core versions prior to 5.6, including related WordPress installations.
What type of attack does CVE-2025-64190 enable?
CVE-2025-64190 enables DOM-Based XSS attacks, allowing attackers to execute malicious scripts in users' browsers.
Is user data at risk due to CVE-2025-64190?
Yes, CVE-2025-64190 can potentially compromise user data by allowing attackers to steal session tokens or sensitive information through XSS.