Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update the WordPress XStore Core Plugin to the latest available version (at least 5.6).
Workaround
No workaround given by the vendor.
Wed, 21 Jan 2026 00:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Jan 2026 23:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 05 Jan 2026 19:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
8theme
8theme xstore Core Wordpress Wordpress wordpress |
|
| Vendors & Products |
8theme
8theme xstore Core Wordpress Wordpress wordpress |
Wed, 31 Dec 2025 05:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 31 Dec 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme.Com XStore Core allows DOM-Based XSS.This issue affects XStore Core: from n/a before 5.6. | |
| Title | WordPress XStore Core plugin < 5.6 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-01-20T14:28:19.393Z
Reserved: 2025-10-29T03:06:57.131Z
Link: CVE-2025-64190
Updated: 2025-12-30T19:41:45.676Z
Status : Awaiting Analysis
Published: 2025-12-30T16:15:45.780
Modified: 2026-01-20T15:18:41.197
Link: CVE-2025-64190
No data.
OpenCVE Enrichment
Updated: 2026-01-05T19:19:57Z