What the vulnerability does
01Description
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
Explanation of Vulnerability in Simple Terms
XStore Core versions up to 5.3.8 contain a privilege management flaw that allows unauthenticated attackers to gain full control of the site over the network. No user interaction or special configuration is required. An attacker can read sensitive data, modify site content, and disrupt service availability.
What an attacker can do
Gain full administrative control of the site without authentication and run arbitrary code.
Potential impact on your site
Complete site compromise: attackers can steal data, modify content, create backdoors, and take the site offline.
Conditions required to exploit
Network access only; no authentication, user interaction, or special setup required.
Key dates
External resources
Related vulnerabilities