What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
Explanation of Vulnerability in Simple Terms
XStore Core versions up to 5.3.5 contain a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code on the site. The vulnerability requires high attack complexity but can affect the entire system when exploited. Site administrators should update to a version newer than 5.3.5 immediately.
What an attacker can do
Run their own code on the site and take full control of it.
Potential impact on your site
Complete compromise of the site, including data theft, malware injection, and loss of availability.
Conditions required to exploit
Network access only; no authentication or user interaction required, though exploitation requires specific technical conditions.
Key dates
External resources
Related vulnerabilities