Locatoraid Store Locator <= 3.9.72 - Unauthenticated SQL Injection
high
The Locatoraid Store Locator plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.9.72. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...
- CVSS:
- 7.5
- Affected:
- up to 3.9.72
- Fixed in:
- 3.9.73
- Disclosed:
- Aug 20, 2026
CVE-2026-66680 on NVD →
Locatoraid Store Locator <= 3.9.65 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scrip...
- CVSS:
- 4.4
- Affected:
- up to 3.9.65
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62140 on NVD →
Locatoraid Store Locator [locatoraid] <= 3.9.65 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.65.
- Affected:
- up to 3.9.65
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62140 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.51 (closed)
unknown
[en] Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50.
- Affected:
- up to 3.9.51
- Fixed in:
- 3.9.51
- Disclosed:
- Jan 7, 2025
CVE-2024-56283 on NVD →
Locatoraid Store Locator <= 3.9.50 - Unauthenticated PHP Object Injection
critical
The Locatoraid Store Locator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.9.50 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain i...
- CVSS:
- 9.8
- Affected:
- up to 3.9.50
- Fixed in:
- 3.9.51
- Disclosed:
- Jan 3, 2025
CVE-2024-56283 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.48 (closed)
unknown
[en] The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 3.9.48
- Fixed in:
- 3.9.48
- Disclosed:
- Oct 16, 2024
CVE-2024-9652 on NVD →
Locatoraid Store Locator <= 3.9.47 - Reflected Cross-Site Scripting
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 3.9.47
- Fixed in:
- 3.9.48
- Disclosed:
- Oct 15, 2024
CVE-2024-9652 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.31 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.30.
- Affected:
- up to 3.9.31
- Fixed in:
- 3.9.31
- Disclosed:
- Mar 27, 2024
CVE-2024-30181 on NVD →
Locatoraid Store Locator <= 3.9.30 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.9.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...
- CVSS:
- 5.5
- Affected:
- up to 3.9.30
- Fixed in:
- 3.9.31
- Disclosed:
- Mar 25, 2024
CVE-2024-30181 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.24 (closed)
unknown
[en] The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
- Affected:
- up to 3.9.24
- Fixed in:
- 3.9.24
- Disclosed:
- Sep 25, 2023
CVE-2023-4476 on NVD →
Locatoraid Store Locator <= 3.9.23 - Reflected Cross-Site Scripting
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lpr-search' parameter in versions up to, and including, 3.9.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 3.9.23
- Fixed in:
- 3.9.24
- Disclosed:
- Aug 28, 2023
CVE-2023-4476 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.19 (closed)
unknown
[en] Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 versions.
- Affected:
- up to 3.9.19
- Fixed in:
- 3.9.19
- Disclosed:
- Aug 25, 2023
CVE-2023-32576 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.15 (closed)
unknown
[en] The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contr...
- Affected:
- up to 3.9.15
- Fixed in:
- 3.9.15
- Disclosed:
- Jun 9, 2023
CVE-2023-2031 on NVD →
Locatoraid Store Locator <= 3.9.18 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 3.9.18
- Fixed in:
- 3.9.19
- Disclosed:
- May 11, 2023
CVE-2023-32576 on NVD →
Locatoraid Store Locator <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributo...
- CVSS:
- 5.4
- Affected:
- up to 3.9.14
- Fixed in:
- 3.9.15
- Disclosed:
- Apr 17, 2023
CVE-2023-2031 on NVD →
Locatoraid Store Locator [locatoraid] < 3.9.12 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.12
- Disclosed:
- Mar 15, 2023
CVE-2023-25709 on NVD →
Locatoraid Store Locator <= 3.9.11 - Cross Site Request Forgery in grab
medium
The Locatoraid Store Locator plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.11. This is due to missing or incorrect nonce validation on the grab function. This makes it possible for unauthenticated attackers to perform unauthorized form submissions via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.12
- Disclosed:
- Feb 14, 2023
CVE-2023-25709 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database