Unauthenticated SQL Injection in Locatoraid Store Locator Plugin by WordPress
CVE-2026-66680
9.3CRITICAL
What is CVE-2026-66680?
The Locatoraid Store Locator plugin for WordPress is vulnerable to unauthenticated SQL injection, which could allow attackers to execute malicious SQL queries. If exploited, this vulnerability may lead to unauthorized access to sensitive data within the database. Users with affected versions (<= 3.9.72) are advised to update the plugin to mitigate potential security risks.
Affected Version(s)
Locatoraid Store Locator <= 3.9.72