plugin

String Locator Vulnerabilities

8 known security issues reported for the String Locator WordPress plugin. Most recent disclosed Jan 21, 2025.

2 high 2 medium

Running String Locator on your site? Check whether your installed version is affected.

Scan your site free

String locator [string-locator] < 2.6.7

unknown

[en] The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is presen...

Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Jan 21, 2025

CVE-2024-10936 on NVD →

String Locator <= 2.6.6 - Unauthenticated PHP Object Injection

high

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in...

CVSS:
8.8
Affected:
up to 2.6.6
Fixed in:
2.6.7
Disclosed:
Jan 20, 2025

CVE-2024-10936 on NVD →

String locator [string-locator] < 2.6.6

unknown

[en] The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
Aug 24, 2024

CVE-2023-6987 on NVD →

String Locator <= 2.6.5 - Reflected Cross-Site Scripting

medium

The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 2.6.5
Fixed in:
2.6.6
Disclosed:
Aug 23, 2024

CVE-2023-6987 on NVD →

String locator [string-locator] < 2.6.0

unknown

[en] The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performin...

Affected:
up to 2.6.0
Fixed in:
2.6.0
Disclosed:
Sep 6, 2022

CVE-2022-2434 on NVD →

String Locator <= 2.5.0 - Cross-Site Request Forgery to PHAR Deserialization

high

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an...

CVSS:
8.8
Affected:
up to 2.5.0
Fixed in:
2.6.0
Disclosed:
Aug 8, 2022

CVE-2022-2434 on NVD →

String locator [string-locator] < 2.5.0

unknown

[en] The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which wi...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 28, 2022

CVE-2022-0493 on NVD →

String Locator <= 2.4.2 - Authenticated Arbitrary File Read

medium

The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be...

CVSS:
4.9
Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 1, 2022

CVE-2022-0493 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database