CVE-2026-25306: WordPress XStore Core plugin <= 5.6.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25306?
CVE-2026-25306 is classified as a high-severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-25306?
To fix CVE-2026-25306, update the 8theme XStore Core plugin to version 5.6.5 or higher.
What types of attacks can CVE-2026-25306 facilitate?
CVE-2026-25306 can facilitate reflected cross-site scripting attacks, allowing attackers to execute arbitrary scripts in the context of a user's session.
Which versions of the XStore Core plugin are affected by CVE-2026-25306?
CVE-2026-25306 affects all versions of the XStore Core plugin from the initial release up to and including version 5.6.4.
Is user data at risk due to CVE-2026-25306?
Yes, user data can be at risk due to CVE-2026-25306, as it may allow malicious scripts to access sensitive information.