CVE-2025-64193: WordPress XStore theme < 9.6.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64193?
CVE-2025-64193 is classified as a high severity vulnerability due to its potential for local file inclusion, which can lead to arbitrary code execution.
How do I fix CVE-2025-64193?
To fix CVE-2025-64193, upgrade the XStore theme to version 9.6.1 or later immediately.
What is the impact of CVE-2025-64193?
CVE-2025-64193 can allow attackers to execute local files on the server, compromising the security and integrity of the application.
Which versions are affected by CVE-2025-64193?
CVE-2025-64193 affects all versions of 8theme XStore prior to 9.6.1.
Is CVE-2025-64193 specific to WordPress installations?
Yes, CVE-2025-64193 specifically affects the XStore theme used in WordPress environments.