CVE-2025-64191: WordPress XStore theme < 9.6.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64191?
The severity of CVE-2025-64191 is considered to be medium, due to its potential for allowing reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-64191?
To fix CVE-2025-64191, you should update the XStore theme to version 9.6.1 or later to mitigate the vulnerability.
What is the impact of CVE-2025-64191?
CVE-2025-64191 allows an attacker to execute arbitrary JavaScript in the context of a user's browser, potentially leading to session hijacking or data theft.
Which versions of XStore are affected by CVE-2025-64191?
CVE-2025-64191 affects all versions of the XStore theme prior to version 9.6.1.
Is CVE-2025-64191 a client-side or server-side vulnerability?
CVE-2025-64191 is a client-side vulnerability as it exploits the way user input is handled in web pages, leading to XSS attacks.