CVE-2021-24289: Store Locator Plus <= 5.5.14 - Authenticated Privilege Escalation

Published May 17, 2021
·
Updated

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

Affected Software

1 affected component
De-baat Store Locator Plus Wordpress<=5.5.14

Event History

May 17, 2021
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-24289?

CVE-2021-24289 is considered a high severity vulnerability due to its potential to allow authenticated users to gain administrative access.

2

How do I fix CVE-2021-24289?

To fix CVE-2021-24289, you should update the Store Locator Plus for WordPress plugin to a version higher than 5.5.14.

3

Who is affected by CVE-2021-24289?

CVE-2021-24289 affects users of the Store Locator Plus for WordPress plugin version 5.5.14 and earlier.

4

What types of attacks can CVE-2021-24289 enable?

CVE-2021-24289 can enable attacks that allow authenticated users to escalate their privileges to that of an administrator.

5

Are there any known exploits for CVE-2021-24289?

Yes, there are known exploits for CVE-2021-24289 that have been reported, which aim to take advantage of the vulnerability to gain unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203