Record summary

CVE-2023-4151 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Store Locator WordPress

Default status: unaffected

CVE ListBefore 1.4.13affected

Nuclei templates

1
ProjectDiscoveryMEDIUMStore Locator WordPress < 1.4.13 - Cross-Site ScriptingCVSS 6.1

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Impact

Attackers can potentially exploit this vulnerability to gain unauthorized access to sensitive information.

Remediation

Update the plugin to Latest version. Fixed in 1.4.13.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023wpwordpresswp-pluginagile-store-locatorxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:agilelogix:store_locator:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/agile-store-locator/"
FOFA: body="/wp-content/plugins/agile-store-locator"

Source: ProjectDiscovery

References

2