CVE-2026-3326: Unknown Xstore

High severity, CVSS 8.6. EPSS: 1.6% chance of exploitation in the next 30 days.

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Affected products

  • Unknown Xstore: before 9.7.3 (fixed in 9.7.3)

Published 2026-06-10. Last modified 2026-07-23.