CVE-2026-94681: WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
Affected Software
1 affected component
WordPress WP Store Locator<3.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Store Locator pluginto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using WP Store Locator versions earlier than 3.0.0 are affected.
2
Does exploitation require authentication or user interaction?
No. The vulnerability is unauthenticated and does not require user interaction, but exploitation has high attack complexity.
3
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service. The provided severity vector indicates availability impact only, with no stated confidentiality or integrity impact.