CVE-2026-25306 is a high-severity Reflected Cross-site Scripting (XSS) vulnerability, identified as CWE-79, affecting the 8theme XStore Core et-core-plugin in versions up to and including 5.6.4. This vulnerability carries a CVSS score of 7.1, indicating it can be exploited remotely with low complexity, though it requires user interaction to succeed, potentially leading to low impacts on confidentiality, integrity, and availability. While not listed on CISA's Known Exploited Vulnerabilities catalog, and with no public exploit code available in common repositories like Metasploit or ExploitDB, its FAUCET Risk Score is 46.0/100. Despite the lack of official exploit intelligence, recent community discussions suggest some sources claim exploit code exists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.6.4CPE match | cpe:2.3:a:8theme:xstore_core:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.