Uncovered Reflected Cross-Site Scripting Vulnerability in Store Locator Plugin
CVE-2024-9652
Summary
The Locatoraid Store Locator plugin for WordPress exposes a serious security flaw through reflected cross-site scripting, allowing attackers to exploit insufficient sanitization of user input. This vulnerability affects all versions of the plugin up to and including 3.9.47, enabling unauthenticated users to inject malicious scripts that can execute in the context of a victim's browser. An attacker can leverage this by tricking users into clicking specially crafted links, potentially leading to unauthorized actions and data theft. It is crucial for website administrators using this plugin to implement necessary security measures and ensure their installations are updated to mitigate risk.
Affected Version(s)
Locatoraid Store Locator * <= 3.9.47
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved