Vulnerabilities and security researches forwp-multi-store-locator wp-multi-store-locator
Direction: ascendingJun 07, 2024
WP Multi Store Locator # CVE-2023-0152
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 05, 2023
- Research Description
- The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 05, 2025
WP Multi Store Locator # CVE-2024-12475
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 04, 2025
- Research Description
- The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 29, 2025
WP Multi Store Locator # CVE-2025-24680
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 27, 2025
- Research Description
- Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Feb 27, 2025
WP Multi Store Locator # CVE-2025-26974
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 25, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multi Store Locator allows Blind SQL Injection. This issue affects WP Multi Store Locator: from n/a through 2.5.1.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Mar 28, 2025
WP Multi Store Locator # CVE-2025-28898
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 26, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Multistore Locator allows SQL Injection. This issue affects WP Multistore Locator: from n/a through 2.5.2.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 03, 2025
WP Multi Store Locator # CVE-2025-31888
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator allows Cross Site Request Forgery. This issue affects WP Multistore Locator: from n/a through 2.5.2.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable