PT-2025-52158 · WordPress · Xstore

Rafie Muhammad

·

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-64193

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 8theme XStore versions prior to 9.6.1
Description An improper control of filename for include/require statement exists in PHP, potentially leading to PHP Local File Inclusion. This issue is present in 8theme XStore.
Recommendations Update 8theme XStore to version 9.6.1 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-64193

Affected Products

Xstore