SQL Injection Vulnerability in WP Multi Store Locator Pro Plugin by WordPress
CVE-2026-15275
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-15275?
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to SQL Injection through the 'store_locatore_search_radius' parameter. This vulnerability arises from inadequate input escaping and improper preparation of the SQL query, allowing unauthenticated attackers to inject additional SQL queries. This access can lead to the extraction of sensitive database information. The vulnerability specifically occurs in a numeric, unquoted SQL context, allowing standard protections to be bypassed. Without nonce or capability checks, the AJAX handler can be exploited by anyone without authentication, posing a significant threat to the security of data on the affected systems.
Affected Version(s)
WP Multi Store Locator Pro 0 <= 4.5.1