Store Locator Plus <= 5.5.15 - Unauthenticated Stored Cross-Site Scripting (XSS)
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 0.8%
from disclosure to weapon
Published on NVDMay 17
VulnCheck+980d
exploitation probability
0.8%top 44% of all CVEs
observed exploitation
yesVulnCheck
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
Affected products
Store Locator Plus® · Store Locator Plus for WordPress