CVE-2025-24680: WordPress WP Multi Store Locator Plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Reflected XSS.This issue affects WP Multistore Locator: from n/a through <= 2.4.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24680?
CVE-2025-24680 has been classified as a high severity vulnerability due to its potential for allowing reflected XSS attacks.
How do I fix CVE-2025-24680?
To fix CVE-2025-24680, update the WP Multi Store Locator plugin to version 2.4.8 or later.
What types of attacks can CVE-2025-24680 enable?
CVE-2025-24680 can enable attackers to execute reflected XSS attacks on users visiting vulnerable sites.
Which versions of WP Multi Store Locator are affected by CVE-2025-24680?
CVE-2025-24680 affects all versions of WP Multi Store Locator up to and including version 2.4.7.
Is user data at risk with CVE-2025-24680?
Yes, user data is at risk as attackers can exploit this vulnerability to execute malicious scripts in the context of affected users.