MEDIUM
WP Store Locator
CVE published 2026-10-08
CVE-2026-105078
The WP Store Locator plugin for WordPress has a stored XSS vulnerability in versions up to 3.0.3. This Cross-site Scripting vulnerability allows an attacker to inject malicious JavaScript code, potentially leading to unauthorized actions or data theft. Defenders responsible for WordPress installations with the WP Store Locator plugin should assess exposure and prioritize updates or mitigations. The CVE re [truncated]