Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3874 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7. |
Fixes
Solution
Update the WordPress WP Multi Store Locator wordpress plugin to the latest available version (at least 2.5.1).
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpexperts
Wpexperts wp Multi Store Locator |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wpexperts:wp_multi_store_locator:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpexperts
Wpexperts wp Multi Store Locator |
Mon, 27 Jan 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7. | |
| Title | WordPress WP Multi Store Locator Plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-02-12T20:41:35.222Z
Reserved: 2025-01-23T14:52:05.567Z
Link: CVE-2025-24680
No data.
Status : Analyzed
Published: 2025-01-27T15:15:15.863
Modified: 2025-02-25T20:02:21.373
Link: CVE-2025-24680
No data.
OpenCVE Enrichment
No data.
EUVD