Unauthenticated SQL Injection in Locatoraid Store Locator Plugin by WordPress
CVE-2026-66680

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-66680?

The Locatoraid Store Locator plugin for WordPress is vulnerable to unauthenticated SQL injection, which could allow attackers to execute malicious SQL queries. If exploited, this vulnerability may lead to unauthorized access to sensitive data within the database. Users with affected versions (<= 3.9.72) are advised to update the plugin to mitigate potential security risks.

Affected Version(s)

Locatoraid Store Locator <= 3.9.72

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arrester | Patchstack Bug Bounty Program
.