CVE-2026-66680: WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Affected Software
1 affected component
WordPress Locatoraid Store Locator Plugin<=3.9.72
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations are affected?
Locatoraid Store Locator plugin versions 3.9.72 and earlier are affected. The provided data does not identify any configuration requirement or mitigation.
3
What is the potential impact?
The vulnerability is SQL injection with critical severity. Its vector indicates high confidentiality impact and low availability impact, with no integrity impact listed.