Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update the WordPress XStore Core Plugin to the latest available version (at least 5.6).
Workaround
No workaround given by the vendor.
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
8theme
8theme xstore Core Wordpress Wordpress wordpress |
|
| Vendors & Products |
8theme
8theme xstore Core Wordpress Wordpress wordpress |
Tue, 30 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme.Com XStore Core allows DOM-Based XSS.This issue affects XStore Core: from n/a before 5.6. | |
| Title | WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-12-30T19:41:50.835Z
Reserved: 2025-10-29T03:06:57.131Z
Link: CVE-2025-64190
Updated: 2025-12-30T19:41:45.676Z
Status : Awaiting Analysis
Published: 2025-12-30T16:15:45.780
Modified: 2025-12-31T20:42:43.210
Link: CVE-2025-64190
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:19:57Z