Store Locator Plus® Vulnerabilities and Affected Products
Vulnerabilities associated with Store Locator Plus for WordPress.
Products
Clear product- Store Locator Plus for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24290MEDIUM | Store Locator Plus <= 5.5.15 - Unauthenticated Stored Cross-Site Scripting (XSS)There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages. CWE-79May 17, 2021 | CVSS6.1v3.1 | EPSS0.826% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |