plugin

Store Locator Vulnerabilities

5 known security issues reported for the Store Locator WordPress plugin. Most recent disclosed Jan 16, 2025.

3 critical 1 high 1 medium

Running Store Locator on your site? Check whether your installed version is affected.

Scan your site free

Store Locator for WordPress with Google Maps – LotsOfLocales <= 3.98.10 - Unauthenticated Local File Inclusion

high

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.98.10. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in...

CVSS:
8.1
Affected:
up to 3.98.10
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23422 on NVD →

Store Locator <= 3.98.10 - Unauthenticated Local File Inclusion

critical

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code i...

CVSS:
9.8
Affected:
3.98.9 – 3.98.9
Fix:
No patched version reported
Disclosed:
Dec 19, 2024

CVE-2024-12571 on NVD →

Store Locator <= 3.98.7 - Cross-Site Request Forgery to Settings Update

medium

The Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.98.7. This is due to missing or incorrect nonce validation when updating settings. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can t...

CVSS:
4.3
Affected:
up to 3.98.7
Fixed in:
3.98.8
Disclosed:
Mar 15, 2023

CVE-2022-47446 on NVD →

Store Locator < 3.34 - SQL Injection

critical

The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] parameter in versions before 3.34 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

CVSS:
9.8
Affected:
up to 3.34
Fixed in:
3.34
Disclosed:
Feb 9, 2015

Store Locator 2.3 - 3.11 - SQL Injection

critical

SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. The Store Locator plugin for WordPress is vulnerable to generic SQL Injection in versions between, and including, 2.3 and 3.1...

CVSS:
9.8
Affected:
up to 3.12
Fixed in:
3.12
Disclosed:
Nov 5, 2014

CVE-2014-8621 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database