First published: Fri Jan 24 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Store Locator allows PHP Local File Inclusion. This issue affects Store Locator: from n/a through 3.98.10.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Store Locator | >=n/a<=3.98.10 | |
WordPress Store Locator | <=3.98.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23422 has a medium severity rating due to its potential for local file inclusion attacks.
To fix CVE-2025-23422, update NotFound Store Locator to version 3.98.11 or later.
CVE-2025-23422 affects NotFound Store Locator versions from n/a through 3.98.10.
Yes, CVE-2025-23422 can allow unauthorized access to sensitive files via path traversal exploits.
Yes, consider using other plugins with similar functionality that are actively maintained and do not have known vulnerabilities.