Locatoraid Store Locator
locatoraid · plugin
Known security vulnerabilities for Locatoraid Store Locator. Find out in seconds which version runs on your site with WP Lens.
8 known vulnerabilities
1 critical · 4 exploitable without logging in · latest Aug 20, 2026
Listed on wordpress.org · latest 3.9.73 · last updated Aug 20, 2026 · 1K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.3
CVE-2026-66680unauthenticated≤ 3.9.72
WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability
- High 8.8
CVE-2023-25709unauthenticated · needs a click≤ 3.9.11
WordPress Locatoraid Store Locator Plugin <= 3.9.11 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.1
CVE-2024-56283unauthenticated≤ 3.9.50
WordPress Locatoraid Store Locator Plugin <= 3.9.50 - PHP Object Injection vulnerability
- Medium 6.1
CVE-2024-9652unauthenticated · needs a click≤ 3.9.47
Locatoraid Store Locator <= 3.9.47 - Reflected Cross-Site Scripting
- Medium 5.9
CVE-2025-62140high privilege≤ 3.9.68
WordPress Locatoraid Store Locator plugin <= 3.9.68 - Cross Site Scripting (XSS) vulnerability
- Medium 5.9
CVE-2024-30181high privilege≤ 3.9.30
WordPress Locatoraid Store Locator plugin <= 3.9.30 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2023-32576subscriber+≤ 3.9.18
WordPress Locatoraid Store Locator Plugin <= 3.9.18 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.4
CVE-2023-2031contributor+≤ 3.9.14
Locatoraid Store Locator <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).