Object Injection Vulnerability in Locatoraid Store Locator by Plainware
CVE-2024-56283

8.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 January 2025

Summary

A deserialization of untrusted data vulnerability has been identified in the Locatoraid Store Locator, developed by Plainware. This flaw allows for object injection, enabling potential attackers to exploit the application by injecting malicious objects into the process. This can result in unauthorized actions or data exposure, particularly in versions of Locatoraid Store Locator ranging from n/a to 3.9.50. Users are advised to mitigate risks associated with this vulnerability through immediate updates or patches.

Affected Version(s)

Locatoraid Store Locator <= 3.9.50

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.