CVE-2024-33551

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:8theme:xstore_core:*:*:*:*:*:wordpress:*:*

History

28 Apr 2026, 19:25

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

21 Feb 2025, 19:15

Type Values Removed Values Added
CPE cpe:2.3:a:8theme:xstore_core:*:*:*:*:*:wordpress:*:*
References () https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
First Time 8theme
8theme xstore Core

21 Nov 2024, 09:17

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve -
Summary
  • (es) La neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en 8theme XStore Core permite la inyección SQL. Este problema afecta a XStore Core: desde n/a hasta 5.3.5.

29 Apr 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-29 06:15

Updated : 2026-04-28 19:25


NVD link : CVE-2024-33551

Mitre link : CVE-2024-33551

CVE.ORG link : CVE-2024-33551


JSON object : View

Products Affected

8theme

  • xstore_core
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')