Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

XStore Core Plugin Allows Harmful Code to Run on Your Website

CVE-2026-25307
Summary

A security issue in the XStore Core plugin allows attackers to inject malicious code onto your website through user input. This could potentially allow them to steal sensitive information or take control of your site. Update the XStore Core plugin to version 5.7 or later to fix this issue.

Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.
nvd CVSS3.1 6.5
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026