8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
AI Analysis
Unauthenticated SQL injection vulnerability in Xstore WordPress theme before 9.7.3
Basic Information
ID
CVE-2026-3326
Source
WPScan
Published
Jun 10, 2026 at 06:00
Modified
Jun 10, 2026 at 10:42
Affected Product
Vendor
Unknown
Product
Xstore
Affected Versions
Unknown Xstore 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
8Theme
Product
Xstore
Version
< 9.7.3