First published: Mon Jan 27 2025(Updated: )
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Multi Store Locator | <=2.4.7 |
Update the WordPress WP Multi Store Locator wordpress plugin to the latest available version (at least 2.5.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24680 has been classified as a high severity vulnerability due to its potential for allowing reflected XSS attacks.
To fix CVE-2025-24680, update the WP Multi Store Locator plugin to version 2.4.8 or later.
CVE-2025-24680 can enable attackers to execute reflected XSS attacks on users visiting vulnerable sites.
CVE-2025-24680 affects all versions of WP Multi Store Locator up to and including version 2.4.7.
Yes, user data is at risk as attackers can exploit this vulnerability to execute malicious scripts in the context of affected users.