plugin

Wp Multi Store Locator Vulnerabilities

12 known security issues reported for the Wp Multi Store Locator WordPress plugin. Most recent disclosed Apr 1, 2025.

2 high 4 medium

Running Wp Multi Store Locator on your site? Check whether your installed version is affected.

Scan your site free

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] <= 2.5.2 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator allows Cross Site Request Forgery. This issue affects WP Multistore Locator: from n/a through 2.5.2.

Affected:
up to 2.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31888 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] <= 2.5.2 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Multistore Locator allows SQL Injection. This issue affects WP Multistore Locator: from n/a through 2.5.2.

Affected:
up to 2.5.2
Fix:
No patched version reported
Disclosed:
Mar 26, 2025

CVE-2025-28898 on NVD →

WP Multistore Locator <= 2.5.2 - Unauthenticated SQL Injection

high

The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
7.5
Affected:
up to 2.5.2
Fix:
No patched version reported
Disclosed:
Mar 24, 2025

CVE-2025-28898 on NVD →

WP Multistore Locator <= 2.5.2 - Cross-Site Request Forgery

medium

The WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attack...

CVSS:
4.3
Affected:
up to 2.5.2
Fix:
No patched version reported
Disclosed:
Mar 12, 2025

CVE-2025-31888 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] < 2.5.2 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multi Store Locator allows Blind SQL Injection. This issue affects WP Multi Store Locator: from n/a through 2.5.1.

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Feb 25, 2025

CVE-2025-26974 on NVD →

WP Multistore Locator <= 2.5.1 - Unauthenticated SQL Injection

high

The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
7.5
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Feb 23, 2025

CVE-2025-26974 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps <= 2.5.0 - Reflected Cross-Site Scripting

medium

The WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

CVSS:
6.1
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jan 27, 2025

CVE-2025-24680 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] < 2.5.1 (closed)

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jan 27, 2025

CVE-2025-24680 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] < 2.4.6 (closed)

unknown

[en] The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web s...

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Jan 4, 2025

CVE-2024-12475 on NVD →

WP Multi Store Locator <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 2.4.1
Fixed in:
2.4.6
Disclosed:
Jan 3, 2025

CVE-2024-12475 on NVD →

WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps [wp-multi-store-locator] < 2.5.1 (closed)

unknown

[en] The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jun 5, 2023

CVE-2023-0152 on NVD →

WP Multi Store Locator <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-l...

CVSS:
6.4
Affected:
up to 2.4.9
Fixed in:
2.5.1
Disclosed:
May 12, 2023

CVE-2023-0152 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database