Impact
The vulnerability is a stored XSS flaw that allows an attacker to inject arbitrary JavaScript into pages generated by the Locatoraid Store Locator plugin. This weakness, identified as CWE‑79, could be used to hijack user sessions, deface content, or perform phishing attacks within the victim’s browser environment. The impact is limited to the client side and does not provide direct code execution on the server, but it can compromise the confidentiality and integrity of user interactions with the application.
Affected Systems
The issue exists in plainware Locatoraid Store Locator version 3.9.68 and all earlier releases. No product versions beyond 3.9.68 are affected, and no additional vendors are listed.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a stored XSS payload entered through the plugin’s administrative interface or customer‑facing widgets, which is then rendered on public pages. Requires the attacker to have some level of access to enter malicious content; hence, the exploitation conditions are non‑trivial.
OpenCVE Enrichment