# WP Store Locator <= 3.0.3 - Authenticated (Store Locator Manager+) Stored Cross-Site Scripting via Store Marker Meta

- **ID:** WPSEC-2026-0621
- **Plugin:** WP Store Locator (`wp-store-locator`), https://wordpress.org/plugins/wp-store-locator/
- **Affected versions:** from 3.0.0 before 3.1.0
- **Fixed in:** 3.1.0 (Update to 3.1.0 or later.)
- **Severity:** Medium 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions None seen (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-store-locator
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0621/

## Description

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the store marker meta fields in versions 3.0.0 up to, and including, 3.0.3 due to the store meta not being protected from WordPress core's custom field handling, which bypasses the plugin's own validation, and insufficient escaping of the resulting marker URL. This makes it possible for authenticated attackers with the Store Locator Manager role or higher, who can edit stores but lack the unfiltered_html capability, to inject arbitrary web scripts that execute when a user hovers over the store in the search results of a map using OpenStreetMap or Stadia Maps.

## References

- https://wpsec.com/vuln/WPSEC-2026-0621/
- https://plugins.svn.wordpress.org/wp-store-locator/tags/3.1.0/
- https://wordpress.org/plugins/wp-store-locator/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0621/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
