PT-2026-95287 · WordPress · Wp Multi Store Locator

·

CVE-2026-15275

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Multi Store Locator Pro versions prior to 4.5.2
Description An issue exists where unauthenticated attackers can perform SQL Injection by appending additional queries to existing ones to extract sensitive database information. This occurs because the store locatore search radius parameter is not sufficiently escaped or prepared before being used in a SQL query. The flaw is located within a numeric, unquoted SQL context, which bypasses the wp magic quotes() protection. Additionally, the AJAX handler wp ajax nopriv make search request lacks nonce or capability checks, allowing the endpoint to be accessed without authentication.
Recommendations Update to a version newer than 4.5.1. As a temporary mitigation, restrict access to the wp ajax nopriv make search request handler or avoid using the store locatore search radius parameter.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15275

Affected Products

Wp Multi Store Locator