CVEs we hold for 8theme
Records whose assigning authority named 8theme as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-25307WordPress XStore Core plugin < 5.7 - Cross Site Scripting (XSS) vulnerability8theme XStore Core
CVE-2026-25306WordPress XStore Core plugin <= 5.6.4 - Reflected Cross Site Scripting (XSS) vulnerability8theme XStore Core
CVE-2026-25305WordPress XStore theme <= 9.6.4 - Cross Site Scripting (XSS) vulnerability8theme XStore
CVE-2026-25006WordPress XStore theme <= 9.6.4 - Arbitrary Shortcode Execution vulnerability8theme XStore
CVE-2025-64191WordPress XStore theme < 9.6.1 - Cross Site Scripting (XSS) vulnerability8theme XStore
CVE-2025-64190WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability8theme XStore Core
CVE-2025-64189WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability8theme XStore Core
CVE-2025-11746XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion8theme XStore
CVE-2024-33562WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability8theme XStore
CVE-2024-33561WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability8theme XStore
CVE-2024-33560WordPress XStore theme <= 9.3.8 - Unauthenticated Local File Inclusion vulnerability8theme XStore
CVE-2024-33559WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability8theme XStore
CVE-2024-33558WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability8theme XStore Core
CVE-2024-33557WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability8theme XStore Core
CVE-2024-33556WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability8theme XStore Core
CVE-2024-33555WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability8theme XStore Core
CVE-2024-33554WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability8theme XStore Core
CVE-2024-33553WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability8theme XStore Core
CVE-2024-33552WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability8theme XStore Core
CVE-2024-33551WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerability8theme XStore Core
25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.