Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2022-47446
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
0
Attacker Value
Unknown
CVE-2022-4832
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-41615
Disclosure Date: September 28, 2022 (last updated December 22, 2024)
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.
0
Attacker Value
Unknown
CVE-2021-24289
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
0
Attacker Value
Unknown
CVE-2021-24290
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
0
Attacker Value
Unknown
CVE-2014-8621
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
0
Attacker Value
Unknown
CVE-2015-4610
Disclosure Date: June 16, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0