Path Traversal Vulnerability in XStore Allows PHP Local File Inclusion
CVE-2024-33560
9CRITICAL
What is CVE-2024-33560?
The vulnerability in the XStore theme by 8theme pertains to an improper limitation of a pathname to a restricted directory, commonly referred to as a path traversal issue. This flaw allows attackers to exploit how file paths are handled, leading to potential PHP local file inclusion. As a result, unauthorized users could gain access to sensitive files within the web server's filesystem, posing significant risks to the integrity and confidentiality of the application's data. This vulnerability affects various versions of the XStore theme, making it crucial for users to address this issue promptly.
Affected Version(s)
XStore <= 9.3.8