Store Locator WordPress < 1.6.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Store Locator WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 4.4
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Jun 11, 2026
CVE-2026-9060 on NVD →
Agile Store Locator <= 1.6.8 - Authenticated (Admin+) Arbitrary File Read
medium
The Agile Store Locator plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6.8. This is due to missing validation of user-supplied template and section parameters before constructing and reading file paths with file_get_contents, allowing directory traversal outside the intend...
- CVSS:
- 4.9
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- May 23, 2026
CVE-2026-9062 on NVD →
Store Locator WordPress <= 1.6.2 - Authenticated (Contributor+) SQL Injection
medium
The Store Locator WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acc...
- CVSS:
- 6.5
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Dec 14, 2025
CVE-2025-67516 on NVD →
Store Locator WordPress [agile-store-locator] <= 1.6.2 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2.
- Affected:
- up to 1.6.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67516 on NVD →
Store Locator WordPress [agile-store-locator] < 1.5.3
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress allows Upload a Web Shell to a Web Server. This issue affects Store Locator WordPress: from n/a through 1.5.2.
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jun 6, 2025
CVE-2025-49329 on NVD →
Store Locator WordPress [agile-store-locator] < 1.5.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress allows SQL Injection. This issue affects Store Locator WordPress: from n/a through 1.5.1.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jun 6, 2025
CVE-2025-49328 on NVD →
Store Locator WordPress <= 1.5.2 - Authenticated (Admin+) Arbitrary File Upload
high
The Store Locator WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server...
- CVSS:
- 7.2
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jun 5, 2025
CVE-2025-49329 on NVD →
Store Locator WordPress <= 1.5.1 - Authenticated (Administrator+) SQL Injection
medium
The Store Locator WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.9
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jun 5, 2025
CVE-2025-49328 on NVD →
Store Locator WordPress [agile-store-locator] < 1.4.15
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.
- Affected:
- up to 1.4.15
- Fixed in:
- 1.4.15
- Disclosed:
- Apr 18, 2024
CVE-2023-50885 on NVD →
Store Locator WordPress <= 1.4.14 - Authenticated(Administrator+) Directory Traversal to Arbitrary File Deletion
medium
The Store Locator WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.4.14. This makes it possible for authenticated attackers, with administrator access and above, to delete arbitrary files.
- CVSS:
- 6.6
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.15
- Disclosed:
- Dec 26, 2023
CVE-2023-50885 on NVD →
Store Locator WordPress [agile-store-locator] < 1.4.13
unknown
[en] The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 1.4.13
- Fixed in:
- 1.4.13
- Disclosed:
- Sep 4, 2023
CVE-2023-4151 on NVD →
Store Locator WordPress <= 1.4.12 - Reflected Cross-Site Scripting via 'asl-nounce'
medium
The Store Locator WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘asl-nounce’ parameter in versions up to, and including, 1.4.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 1.4.12
- Fixed in:
- 1.4.13
- Disclosed:
- Aug 10, 2023
CVE-2023-4151 on NVD →
Store Locator WordPress [agile-store-locator] < 1.4.10
unknown
[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions.
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.10
- Disclosed:
- Jun 22, 2023
CVE-2023-27618 on NVD →
Store Locator WordPress <= 1.4.9 - Authenticated (Editor+) Stored Cross-Site Scripting via 'category_name', 'description', 'description_2' parameters
medium
The Store Locator WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting 'category_name', 'description', 'description_2' and other form parameters in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers w...
- CVSS:
- 4.4
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.10
- Disclosed:
- Mar 20, 2023
CVE-2023-27618 on NVD →
Store Locator WordPress [agile-store-locator] < 1.4.9
unknown
[en] The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as ad...
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
- Disclosed:
- Jan 23, 2023
CVE-2022-4832 on NVD →
Store Locator WordPress <= 1.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Store Locator WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor le...
- CVSS:
- 6.4
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Dec 24, 2022
CVE-2022-4832 on NVD →
Store Locator WordPress [agile-store-locator] < 1.4.6
unknown
[en] Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Nov 18, 2022
CVE-2022-41615 on NVD →
Store Locator WordPress <= 1.4.5 - Cross-Site Request Forgery to Cross-Site Scripting
high
The Store Locator WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5. This is due to missing or incorrect nonce validation on the handle_request function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malic...
- CVSS:
- 8.8
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Sep 28, 2022
CVE-2022-41615 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database