Stored Cross-Site Scripting Vulnerability in WP Store Locator Plugin by WordPress
CVE-2026-3361
6.4MEDIUM
What is CVE-2026-3361?
The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization of user input and failure to properly escape output. This vulnerability allows authenticated attackers with contributor-level access to inject malicious web scripts via the 'wpsl_address' post meta value. The injected scripts can be executed when users access pages containing compromised map marker info windows.
Affected Version(s)
WP Store Locator 0 <= 2.2.261