PT-2026-34631 · Tijmen Smit · Store Locator

Supanat Konprom

·

Published

2026-04-23

·

Updated

2026-04-23

·

CVE-2026-3361

CVSS v3.1

6.4

Medium

AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl address' post meta value in versions up to, and including, 2.2.261 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and opens an injected map marker info window.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3361

Affected Products

Store Locator