Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2023-25709

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.
Attacker Value
Unknown

CVE-2022-4832

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-41615

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.
Attacker Value
Unknown

CVE-2022-36086

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialized with a size smaller than `3 * size_of::<usize>` because of metadata write operations. This vulnerability impacts all the initialization functions on the `Heap` and `LockedHeap` types, including `Heap::new`, `Heap::init`, `Heap::init_from_slice`, and `LockedHeap::new`. It also affects multiple uses of the `Heap::extend` method. Version 0.10.2 contains a patch for the issue. As a workaround, ensure that the heap is only initialized with a size larger than `3 * size_of::<usize>` and that the `Heap::extend` method is only called with sizes larger than `2 * size_of::<usize>()`. Also, ensure that the total heap size is (and stays) a multiple of `2 * size_of::<usize>()`.
Attacker Value
Unknown

CVE-2022-2434

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Attacker Value
Unknown

CVE-2022-0493

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed.
Attacker Value
Unknown

CVE-2021-42563

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
Attacker Value
Unknown

CVE-2021-24289

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
Attacker Value
Unknown

CVE-2021-24290

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
Attacker Value
Unknown

CVE-2016-10939

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.