cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forjsp-store-locator jsp-store-locator

Direction: ascending
Jan 11, 2025

JSP Store Locator # CVE-2024-11267

CVE, Research URL

CVE-2024-11267

Application

JSP Store Locator

Date
May 16, 2025
Research Description
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.
Affected versions
max 1.0.
Status
vulnerable

JSP Store Locator # CVE-2024-12301

CVE, Research URL

CVE-2024-12301

Application

JSP Store Locator

Date
May 16, 2025
Research Description
The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Affected versions
max 1.0.
Status
vulnerable