Junglewise Threat Intelligence

CVE-2026-3326: 8theme XStore SQL injection in AJAX search action

CVE-2026-3326 · Severity: info · CVSS 8.6 · Published 2026-06-10

Executive brief

XStore is a popular WordPress theme used for building e-commerce websites. A security flaw allows unauthenticated attackers to execute malicious database commands by sending a specially crafted web request. This could lead to the theft of sensitive customer data, unauthorized access to administrative accounts, or complete compromise of the website's database.

Technical details

An unauthenticated SQL injection vulnerability exists in the XStore WordPress theme before version 9.7.3. The flaw is located within an AJAX action (triggered via the 'et_search' parameter) that fails to properly sanitize and escape user-supplied input before incorporating it into a SQL query. An attacker can exploit this by sending a crafted GET request to the site's search functionality, as demonstrated by time-based blind SQL injection payloads. This allows for unauthorized data extraction from the WordPress database. The issue is resolved in version 9.7.3.

Affected products

  • 8theme XStore < 9.7.3

Timeline

  • 2026-05-20: disclosed: Publicly published by WPScan
  • 2026-05-20: patched: Fixed in version 9.7.3
  • 2026-06-10: advisory: NVD published the CVE record

References