Store Locator for WordPress with Google Maps – LotsOfLocales <= 3.98.10 - Unauthenticated Local File Inclusion
high
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.98.10. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in...
- CVSS:
- 8.1
- Affected:
- up to 3.98.10
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2025
CVE-2025-23422 on NVD →
Store Locator <= 3.98.10 - Unauthenticated Local File Inclusion
critical
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code i...
- CVSS:
- 9.8
- Affected:
- 3.98.9 – 3.98.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 19, 2024
CVE-2024-12571 on NVD →
Store Locator <= 3.98.7 - Cross-Site Request Forgery to Settings Update
medium
The Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.98.7. This is due to missing or incorrect nonce validation when updating settings. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 3.98.7
- Fixed in:
- 3.98.8
- Disclosed:
- Mar 15, 2023
CVE-2022-47446 on NVD →
Store Locator < 3.34 - SQL Injection
critical
The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] parameter in versions before 3.34 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- CVSS:
- 9.8
- Affected:
- up to 3.34
- Fixed in:
- 3.34
- Disclosed:
- Feb 9, 2015
Store Locator 2.3 - 3.11 - SQL Injection
critical
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
The Store Locator plugin for WordPress is vulnerable to generic SQL Injection in versions between, and including, 2.3 and 3.1...
- CVSS:
- 9.8
- Affected:
- up to 3.12
- Fixed in:
- 3.12
- Disclosed:
- Nov 5, 2014
CVE-2014-8621 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database