Executive brief
XStore is a popular WordPress theme used for building e-commerce websites. A security flaw allows unauthenticated attackers to execute malicious database commands by sending a specially crafted web request. This could lead to the theft of sensitive customer data, unauthorized access to administrative accounts, or complete compromise of the website's database.
Technical details
An unauthenticated SQL injection vulnerability exists in the XStore WordPress theme before version 9.7.3. The flaw is located within an AJAX action (triggered via the 'et_search' parameter) that fails to properly sanitize and escape user-supplied input before incorporating it into a SQL query. An attacker can exploit this by sending a crafted GET request to the site's search functionality, as demonstrated by time-based blind SQL injection payloads. This allows for unauthorized data extraction from the WordPress database. The issue is resolved in version 9.7.3.
Affected products
- 8theme XStore < 9.7.3
Timeline
- 2026-05-20: disclosed: Publicly published by WPScan
- 2026-05-20: patched: Fixed in version 9.7.3
- 2026-06-10: advisory: NVD published the CVE record