Sceawere
Vulnerability Detail
CVE-2026-105078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Store Locator Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- WP Store Locator
- Product
- WP Store Locator
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Store Locator WP Store Locator wp-store-locator allows Stored XSS.This issue affects WP Store Locator: from n/a through 3.0.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T13:17:12.903Z",
"pubdate": "2026-10-08T13:17:12.903Z",
"executiveSummary": "The WP Store Locator plugin, versions 3.0.3 and below, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and persist malicious scripts within the application's database.\nThe primary risk associated with this vulnerability is the execution of arbitrary JavaScript in the context of an authenticated administrator's or visitor's browser session. By successfully exploiting this flaw, an attacker could potentially hijack user sessions, perform unauthorized administrative actions, redirect users to malicious websites, or capture sensitive data displayed on the compromised page. The vulnerability effectively turns the affected store locator component into a vector for delivering malicious payloads to victims viewing the storefront or administrative interface. Given that XSS can lead to full compromise of the user's interaction with the affected site, this issue carries a significant security risk for installations running the vulnerable versions.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (CWE-79), resulting from the failure to adequately sanitize, validate, or encode input before rendering it in the browser. In the WP Store Locator plugin, specific input fields—likely those associated with store metadata, addresses, or configuration settings—do not implement sufficient output encoding or input filtering. This lack of sanitization allows an attacker to inject executable scripts directly into the database.\nThe attack flow begins with the submission of a malicious payload through an input vector exposed by the plugin. Because the application fails to neutralize the input, the browser interprets the script as legitimate code rather than harmless data. When an authorized user, such as a store manager or site administrator, accesses the administrative dashboard or a visitor views the front-end page where the location data is rendered, the payload is executed within their browser session. Since the script executes in the context of the user's session, it gains the same origin permissions as the legitimate application.\nTechnically, the issue persists because the plugin fails to utilize secure WordPress development practices for output rendering, such as properly applying esc_html(), esc_attr(), or similar functions to user-controlled data before it is emitted to the Document Object Model (DOM). By injecting a script tag or an event handler (e.g., onload, onerror), an attacker can trigger unauthorized actions. The scope of the impact depends on the privileges of the user viewing the compromised page. If an administrator views the location details, the attacker may be able to perform actions on their behalf, such as creating new administrative accounts, modifying plugin settings, or exfiltrating non-public data. Even if the impact is limited to front-end visitors, the attacker can leverage the XSS to harvest cookies, perform phishing attacks, or inject malicious content into the site's layout. The vulnerability affects all versions of WP Store Locator from the initial release up to and including 3.0.3."
}