Stored Cross-Site Scripting Vulnerability in WP Store Locator Plugin by WordPress
CVE-2026-3361

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 April 2026

What is CVE-2026-3361?

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization of user input and failure to properly escape output. This vulnerability allows authenticated attackers with contributor-level access to inject malicious web scripts via the 'wpsl_address' post meta value. The injected scripts can be executed when users access pages containing compromised map marker info windows.

Affected Version(s)

WP Store Locator 0 <= 2.2.261

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supanat Konprom
.