nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24290 CVE-2021-24290
MEDIUM
Store Locator Plus <= 5.5.15 - Unauthenticated Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-24290 has a selected CVSS score of 6.1 (medium).
Description
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Store Locator Plus for WordPressBrowse Store Locator Plus® / Store Locator Plus for WordPress | CVE List | 5.5.15 to ≤ 5.5.15 | affected |
store_locator_plusBrowse de-baat / store_locator_plus | VulnCheck | Version data not supplied | |
References
3wpscan.comConfirmation
https://wpscan.com/vulnerability/dc368484-f2fe-4c76-ba3d-e00e7f633719 wordfence.com
https://www.wordfence.com/blog/2021/04/severe-unpatched-vulnerabilities-leads-to-closure-of-store-locator-plus-plugin