PT-2026-48388 · WordPress · Store Locator
CVE-2026-9060
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Store Locator WordPress plugin versions prior to 1.6.6
Description
The plugin fails to sanitize and escape a specific setting before it is stored and subsequently displayed on the administration page. This allows high-privileged users, such as administrators, to execute Stored Cross-Site Scripting (XSS) attacks. This issue persists even when the
unfiltered html capability is disabled, which can impact environments like multisite networks when a super administrator views the page. The vulnerable variable is map style.Recommendations
Update to version 1.6.6 or later.
As a temporary workaround, restrict access to the administration page settings involving the
map style variable to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Store Locator