CVE-2026-3326
published 2026-06-10CVE-2026-3326: The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to…
PriorityP265high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EXPLOIT
EPSS
0.97%
58.0th percentile
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
XStore Theme < 9.7.3 - SQL Injection
nuclei·CVSS 8.6
CVE-2026-3326 [HIGH] XStore Theme < 9.7.3 - SQL Injection
XStore Theme = 5'
- 'status_code != 404'
condition: and
# digest: 490a00463044022079609164d6bb2c4613c0b6c5078ba89a23cd3263710ae6a5f0df934eb695770b0220250313071332da48760a361672cd6c5d75a0c96e7969209c49c9dd57035ee1c5:922c64590222798bb761d5b6d8e72950
2026-06-10
Published