What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
Explanation of Vulnerability in Simple Terms
XStore Core versions up to 5.3.8 contain a path traversal vulnerability that allows authenticated users with low privileges to read, modify, or delete files outside the intended directory. The vulnerability requires network access and high attack complexity, but can affect the entire site if exploited. Site owners should update to a version newer than 5.3.8 immediately.
What an attacker can do
Read, modify, or delete files outside the intended directory on the server.
Potential impact on your site
An authenticated attacker can access sensitive files, alter site configuration, or disrupt availability.
Conditions required to exploit
Attacker must have a low-privilege authenticated account; no user interaction required.
Key dates
External resources
Related vulnerabilities