Skip to content

Known CVE

XStore Theme < 9.7.3 - SQL Injection

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2026-3326

High2026CVSS 8.6CWE-89

cve2026 · wordpress · wp · wp-theme · sqli · xstore

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website