What the vulnerability does
01Description
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
Explanation of Vulnerability in Simple Terms
XStore Core through version 5.3.5 fails to properly check user permissions before allowing access to sensitive data. An authenticated user with low privileges can read information they should not have access to, such as other users' data or configuration details. The vulnerability requires a valid account but no special interaction from the victim.
What an attacker can do
Read sensitive data belonging to other users or the site without authorization.
Potential impact on your site
User data and site information may be exposed to any authenticated user, even those with minimal permissions.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities