Uncovered Reflected Cross-Site Scripting Vulnerability in Store Locator Plugin
CVE-2024-9652

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 October 2024

Summary

The Locatoraid Store Locator plugin for WordPress exposes a serious security flaw through reflected cross-site scripting, allowing attackers to exploit insufficient sanitization of user input. This vulnerability affects all versions of the plugin up to and including 3.9.47, enabling unauthenticated users to inject malicious scripts that can execute in the context of a victim's browser. An attacker can leverage this by tricking users into clicking specially crafted links, potentially leading to unauthorized actions and data theft. It is crucial for website administrators using this plugin to implement necessary security measures and ensure their installations are updated to mitigate risk.

Affected Version(s)

Locatoraid Store Locator * <= 3.9.47

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.