Extension WordPress
Vulnérabilités Store Locator for WordPress with Google Maps – LotsOfLocales
Cette page rassemble les failles publiées pour Store Locator for WordPress with Google Maps – LotsOfLocales, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Store Locator for WordPress with Google Maps – LotsOfLocales
5 fiches
Store Locator for WordPress with Google Maps – LotsOfLocales <= 3.98.10 – Unauthenticated Local File Inclusion
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.98.10. This makes it possible for unauthenticated attackers to include and execute…
*-3.98.10
Non indiqué
16/01/2025
Store Locator <= 3.98.10 – Unauthenticated Local File Inclusion
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary…
3.98.9
Non indiqué
19/12/2024
Store Locator <= 3.98.7 – Cross-Site Request Forgery to Settings Update
The Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.98.7. This is due to missing or incorrect nonce validation when updating settings. This makes it possible for unauthenticated attackers…
*-3.98.7
3.98.8
15/03/2023
Store Locator < 3.34 – SQL Injection
The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] parameter in versions before 3.34 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
[*, 3.34)
3.34
09/02/2015
Store Locator 2.3 – 3.11 – SQL Injection
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. The Store Locator plugin for WordPress is vulnerable to generic SQL…
[*, 3.12)
3.12
05/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.