CVE-2026-3326: XStore < 9.7.3 - Unauthenticated SQLi
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xstore WordPress themeto a version that resolves this vulnerability.Fixed in 9.7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3326?
CVE-2026-3326 has a high severity score of 8.6 as per the CVSS 3.1 standard.
How do I fix CVE-2026-3326?
To fix CVE-2026-3326, upgrade the XStore WordPress theme to version 9.7.3 or later.
What type of vulnerability is CVE-2026-3326?
CVE-2026-3326 is a SQL injection vulnerability affecting the XStore WordPress theme.
Who is affected by CVE-2026-3326?
Users of the XStore WordPress theme prior to version 9.7.3 are affected by CVE-2026-3326.
What can attackers do with CVE-2026-3326?
Attackers can exploit CVE-2026-3326 to execute arbitrary SQL queries leading to unauthorized data access.