Hello.
I just purchased the xstore bundle and installed it on my website. The only thing is that the xstore core plugin is flagged as critical and thereby blocked. What to do?
I have the latest version 5.7.8
This topic has 15 replies, 3 voices, and was last updated 1 week, 2 days ago ago by Tony Rodriguez
Hello.
I just purchased the xstore bundle and installed it on my website. The only thing is that the xstore core plugin is flagged as critical and thereby blocked. What to do?
I have the latest version 5.7.8
access
I run it on a testsite:
https://miniforge3d.nl/curros
Hello @Joris,
The credentials you provided are incorrect for login. Please verify the access details and provide us with the correct information so we can investigate the issue. Additionally, we have attached a screenshot of the notices in the private area.
Best regards,
Jack Richardson
The 8Theme’s Team
There was an error, sorry..
Hello @Joris,
The access credentials are still incorrect. A video has been attached in the private content for your reference. We kindly ask you to respect our support time by ensuring that the credentials are correct before sharing them on our support forum.
Best regards,
Jack Richardson
The 8Theme’s Team
I am very very sorry. The staging site did not copy the users. So i updates them myself today. I tested the logins and tehy work now.
1000 times sorry for the inconfeniance.
Hello @Joris,
Thank you for providing us with the correct credentials. Could you please check the recovery link sent to your email? Upon our testing, it appears that the main issue is caused by some of your additional plugins that use the same code modules as we do, leading to conflicts (https://prnt.sc/vtfSdSz2_9or). We believe the plugin “Envo Extra” might be responsible, as we encountered no issues after disabling a few plugins, including this one, on your staging environment and then activating the XStore Core. The primary reason you could not activate our plugin is that it triggered a fatal error due to incompatibility issues. Therefore, we kindly ask you to review the suggested solution on your end and also provide us with temporary correct FTP access in the private content.
Best Regards,
Jack Richardson
The 8Theme’s Team
Hello, thank you for you reply… I removed all the plugins from envo, and disabled almost every other plugin. Unfortunately it is still flagged as critical.
Hello @Joris,
The FTP access you provided appears to be loading an incorrect directory for your wp-staging website. Additionally, the folder with the same name is empty, as shown in this screenshot: https://prnt.sc/vEFIV6HXXrXK. Please verify the FTP access at your earliest convenience. We also kindly request that you set the PHP version to either 8.0 or 8.2 and check if the critical issues persist.
Upon reviewing the vulnerability issues in your dashboard, there is no information regarding the specific errors or code parts causing the vulnerability (https://prnt.sc/roPeBHDAkayt). Please note that our theme and plugin have been inspected using the https://patchstack.com/ service, and any previously mentioned issues (https://prnt.sc/YL9AZ2RvJQwS) have been addressed and included in our updates. We would like to understand how to identify the source of the vulnerabilities in our plugin, or if the source of such vulnerabilities is cached on Strato services. Therefore, we kindly ask you to contact your Strato services and request a refresh of the check or provide us a details of issues they found in our code so we could fix it and release in next update.
Best Regards,
Jack Richardson
The 8Theme’s Team
I contacted my provider. They use WPscan for checking vulnerabilities. I therefor installed wpscan on my wordpress and did the scan myself. pdf included.
Xcore is flagged critical by wpscan.
The ftp server is not correct. That is true. Strato does not let me access ftp through 3rd party programms. Only through their site.
Hello @Joris,
We have reviewed your PDF analytics template and noted that it references issues related to our XStore Core plugin, but these pertain to a previous versions (https://prnt.sc/zncns8c5OpKi). Your current version of the plugin is 5.7.8, whereas the vulnerabilities mentioned are applicable to XStore Core versions 5.3.5 and earlier. Therefore, there are no errors in the version of XStore Core installed on your website. We recommend that you submit your topic to Strato support to ensure they are checking only the latest versions of plugins and themes. This is important as they might otherwise classify our plugin as vulnerable based on past issues that have already been resolved in updates, and the current version has all fixes implemented.
Best Regards,
Jack Richardson
The 8Theme’s Team
I contacted my provider, but they could not do anything. Then i contacted WPscan, who provides the security. And they found an eroor in their system. They accedentally flagged all xcore versions as critical. They changed their database.
Now when i activate the them it works. (apart from a fatal eroor which was caused by another plugin).
Thank you for your time. And now i have to find out all the features of this theme.
Thank you for the good service and fast replies!
With regards,
Joris
Thanks for the support! My topic “Xstore core is flagged as critical and is blocked” has been successfully resolved.
Dear Joris,
We really appreciate your time and engagement within the WordPress & WooCommerce community
Your feedback drives every improvement we make in XStore — helping us deliver a smoother and more flexible experience with each update.
Leave Feedback →
(takes less than a minute)
Your input makes a real difference.
Topic closed.
The 8Theme Team
The issue related to '‘Xstore core is flagged as critical and is blocked’' has been successfully resolved, and the topic is now closed for further responses