{
 "id": "WPSEC-2026-0621",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0621/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0621/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0621/index.md",
 "title": "WP Store Locator <= 3.0.3 - Authenticated (Store Locator Manager+) Stored Cross-Site Scripting via Store Marker Meta",
 "description": "The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the store marker meta fields in versions 3.0.0 up to, and including, 3.0.3 due to the store meta not being protected from WordPress core's custom field handling, which bypasses the plugin's own validation, and insufficient escaping of the resulting marker URL. This makes it possible for authenticated attackers with the Store Locator Manager role or higher, who can edit stores but lack the unfiltered_html capability, to inject arbitrary web scripts that execute when a user hovers over the store in the search results of a map using OpenStreetMap or Stadia Maps.",
 "plugin": {
  "slug": "wp-store-locator",
  "name": "WP Store Locator",
  "full_name": "WP Store Locator",
  "wordpress_org": "https://wordpress.org/plugins/wp-store-locator/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-store-locator/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-store-locator"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.0.0",
    "from_inclusive": true,
    "to": "3.1.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.0.0 before 3.1.0"
  ]
 },
 "introduced_in": "3.0.0",
 "fixed_in": "3.1.0",
 "remediation": "Update to 3.1.0 or later.",
 "fix_released": "2026-10-07T09:11:25+00:00",
 "published": "2026-10-08T09:45:16+00:00",
 "updated": "2026-10-07T11:22:48.206710+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0621/",
  "https://plugins.svn.wordpress.org/wp-store-locator/tags/3.1.0/",
  "https://wordpress.org/plugins/wp-store-locator/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-store-locator",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "None seen",
  "as_of": "2026-10-08"
 }
}