Arbitrary File Upload Vulnerability in Agile Logix Store Locator by WordPress
CVE-2025-49329
6.6MEDIUM
What is CVE-2025-49329?
The Agile Logix Store Locator plugin for WordPress has a vulnerability that allows an attacker to upload a web shell to the server. This issue permits the uploading of files that could execute malicious scripts, potentially compromising the integrity of the server. Users of versions from n/a to 1.5.2 should ensure they update to the latest version to protect their applications from unauthorized file access and related threats.
Affected Version(s)
Store Locator WordPress <= 1.5.2