CVE-2026-25006: WordPress XStore theme <= 9.6.4 - Arbitrary Shortcode Execution vulnerability
Published Feb 19, 2026
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.
Affected Software
2 affected components
8theme XStore<=9.6.4
WordPress XStore<=9.6.4
Event History
Feb 19, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25006?
CVE-2026-25006 is classified as a high-severity vulnerability due to its ability to allow arbitrary shortcode execution in affected versions of the XStore theme.
2
How do I fix CVE-2026-25006?
To fix CVE-2026-25006, update the XStore theme to version 9.6.5 or later, which addresses the vulnerability.
3
What versions are affected by CVE-2026-25006?
CVE-2026-25006 affects XStore theme versions from n/a through 9.6.4.
4
What type of vulnerability is CVE-2026-25006?
CVE-2026-25006 is an Arbitrary Shortcode Execution vulnerability, also known as a Basic XSS vulnerability.
5
Who is the vendor responsible for CVE-2026-25006?
The vendor responsible for the affected XStore theme in CVE-2026-25006 is 8theme.