PatchSiren

WP Store Locator CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Store Locator CVE published 2026-10-08

CVE-2026-105078

The WP Store Locator plugin for WordPress has a stored XSS vulnerability in versions up to 3.0.3. This Cross-site Scripting vulnerability allows an attacker to inject malicious JavaScript code, potentially leading to unauthorized actions or data theft. Defenders responsible for WordPress installations with the WP Store Locator plugin should assess exposure and prioritize updates or mitigations. The CVE re [truncated]