CVE-2026-25305: WordPress XStore theme <= 9.6.4 - Cross Site Scripting (XSS) vulnerability
Published Feb 19, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4.
Affected Software
2 affected components
8theme XStore<=9.6.4
WordPress XStore theme<=9.6.4
Event History
Feb 19, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25305?
CVE-2026-25305 is classified as a Cross Site Scripting (XSS) vulnerability, which is considered a high severity issue.
2
How do I fix CVE-2026-25305?
To fix CVE-2026-25305, upgrade the XStore theme to the latest version beyond 9.6.4.
3
What versions of XStore are affected by CVE-2026-25305?
CVE-2026-25305 affects XStore theme versions from n/a through 9.6.4.
4
What type of vulnerability is CVE-2026-25305?
CVE-2026-25305 is a Cross Site Scripting (XSS) vulnerability that allows for DOM-Based XSS attacks.
5
Who is the vendor of the affected software in CVE-2026-25305?
The vendor of the affected software in CVE-2026-25305 is 8theme for the XStore theme.