WP Store Locator <= 3.0.3 - Authenticated (Store Locator Manager+) Stored Cross-Site Scripting via Store Marker Meta
- ID
- WPSEC-2026-0621
- Plugin
- WP Store Locator (wp-store-locator)
- Affected
- from 3.0.0 before 3.1.0
- Remediation
- Update to 3.1.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions None seen among sites WPSec scans, 2026-10-08
- Attack surface
- WP Store Locator on WPSec AttackSurface
- Fix released
- Published
Description
The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the store marker meta fields in versions 3.0.0 up to, and including, 3.0.3 due to the store meta not being protected from WordPress core's custom field handling, which bypasses the plugin's own validation, and insufficient escaping of the resulting marker URL. This makes it possible for authenticated attackers with the Store Locator Manager role or higher, who can edit stores but lack the unfiltered_html capability, to inject arbitrary web scripts that execute when a user hovers over the store in the search results of a map using OpenStreetMap or Stadia Maps.
References
- https://wpsec.com/vuln/WPSEC-2026-0621/
- https://plugins.svn.wordpress.org/wp-store-locator/tags/3.1.0/
- https://wordpress.org/plugins/wp-store-locator/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS