Object Injection Vulnerability in WP Store Locator by Tijmen Smit
CVE-2025-52737
8.8HIGH
What is CVE-2025-52737?
A vulnerability exists in the WP Store Locator plugin by Tijmen Smit that permits object injection due to deserialization of untrusted data. This flaw affects all versions of the plugin up to and including 2.2.260, allowing attackers to exploit the plugin and potentially execute malicious code. It is critical for users to update to the latest version to mitigate risks associated with unauthorized access and exploitability of their WordPress sites.
Affected Version(s)
WP Store Locator <= n/a