8theme develops a suite of e-commerce and storefront products centered on its XStore platform, which serves as a widely deployed WordPress-based builder for online retail. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and concentrates on structural weaknesses in authorization and input handling, including missing authorization checks, unsafe deserialization, path traversal, cross-site scripting, and SQL injection—issues characteristic of web applications that integrate user-generated content and database-driven functionality. Defenders should prioritize patches for this vendor's storefront products, as the combination of critical-severity exposure and authorization flaws makes them attractive targets; live exploitation activity and current severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 8theme over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33559CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through | Apr 29, 2024 | 9.3 | 40 | NO | YES |
CVE-2024-33551CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n | Apr 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-11746HIGH The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it pos | Oct 15, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-33556CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. | May 17, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-33561CRITICAL Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. | Jun 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-33553CRITICAL Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5. | Apr 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-25306HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XSto | Mar 25, 2026 | 7.1 | 25 | NO | NO |
CVE-2024-33563HIGH Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. | Jun 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-33555HIGH Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. | Jun 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-33560CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a th | Jun 4, 2024 | 9.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 8theme.
Media articles that mention a CVE ID that affects a product developed by 8theme — matched by CVE ID, not by vendor name.