Vulnerabilities / WP Store Locator / WPSEC-2026-0621

WP Store Locator <= 3.0.3 - Authenticated (Store Locator Manager+) Stored Cross-Site Scripting via Store Marker Meta

Medium 5.5 CWE-79Fixed in 3.1.0
ID
WPSEC-2026-0621
Plugin
WP Store Locator (wp-store-locator)
Affected
from 3.0.0 before 3.1.0
Remediation
Update to 3.1.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions None seen among sites WPSec scans, 2026-10-08
Attack surface
WP Store Locator on WPSec AttackSurface
Fix released
Published

Description

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the store marker meta fields in versions 3.0.0 up to, and including, 3.0.3 due to the store meta not being protected from WordPress core's custom field handling, which bypasses the plugin's own validation, and insufficient escaping of the resulting marker URL. This makes it possible for authenticated attackers with the Store Locator Manager role or higher, who can edit stores but lack the unfiltered_html capability, to inject arbitrary web scripts that execute when a user hovers over the store in the search results of a map using OpenStreetMap or Stadia Maps.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0