Input validation vulnerability in XStore Core 5.3.5

The XStore Core plugin for WordPress has a security issue that affects all versions up to 5.3.5. This vulnerability allows attackers who have subscriber-level access or higher to include and run any type of file on the server. This can be used to bypass security measures, access sensitive information, or execute code. It is a risk especially when uploading images or other seemingly harmless file types.

Detected in:

XStore Core fixed vulnerable versions: >= * <= 5.3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.