PT-2026-48386 · Undefined · Undefined
Ahmed Makawi
·
Published
2026-06-10
·
Updated
2026-06-10
·
CVE-2026-3326
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined