WP Multi Store Locator Reflected Cross-Site Scripting Vulnerability
Vulnerability
Patched
A reflected cross-site scripting vulnerability has been identified in the WP Multi Store Locator WordPress plugin, affecting versions through 2.4.7. This vulnerability arises from improper neutralization of script-related HTML tags, allowing attackers to inject malicious scripts that could be executed when users visit the affected page.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users of the WP Multi Store Locator WordPress plugin should update to version 2.5.1 or later to address this vulnerability. Patchstack users can enable auto-updates for vulnerable plugins.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
