PT-2025-52158 · WordPress · Xstore

·

CVE-2025-64193

·

Published

2025-12-18

·

Updated

2025-12-18

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 8theme XStore versions prior to 9.6.1
Description An improper control of filename for include/require statement exists in PHP, potentially leading to PHP Local File Inclusion. This issue is present in 8theme XStore.
Recommendations Update 8theme XStore to version 9.6.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64193

Affected Products

Xstore