Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68.
Published: 2025-12-31
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored XSS flaw that allows an attacker to inject arbitrary JavaScript into pages generated by the Locatoraid Store Locator plugin. This weakness, identified as CWE‑79, could be used to hijack user sessions, deface content, or perform phishing attacks within the victim’s browser environment. The impact is limited to the client side and does not provide direct code execution on the server, but it can compromise the confidentiality and integrity of user interactions with the application.

Affected Systems

The issue exists in plainware Locatoraid Store Locator version 3.9.68 and all earlier releases. No product versions beyond 3.9.68 are affected, and no additional vendors are listed.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a stored XSS payload entered through the plugin’s administrative interface or customer‑facing widgets, which is then rendered on public pages. Requires the attacker to have some level of access to enter malicious content; hence, the exploitation conditions are non‑trivial.

Generated by OpenCVE AI on April 29, 2026 at 18:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version newer than 3.9.68 once it is released by plainware.
  • If an update is not immediately available, deactivate or uninstall the Locatoraid Store Locator plugin to eliminate the attack surface.
  • Ensure that any user‑generated content handled by the plugin is sanitised using a library such as WordPress’s built‑in wp_kses() before rendering.

Generated by OpenCVE AI on April 29, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.65. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68.
Title WordPress Locatoraid Store Locator plugin <= 3.9.65 - Cross Site Scripting (XSS) vulnerability WordPress Locatoraid Store Locator plugin <= 3.9.68 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Plainwaire
Plainwaire locatoraid Store Locator
Wordpress
Wordpress wordpress
Vendors & Products Plainwaire
Plainwaire locatoraid Store Locator
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.65.
Title WordPress Locatoraid Store Locator plugin <= 3.9.65 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Plainwaire Locatoraid Store Locator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:03.097Z

Reserved: 2025-10-07T15:41:47.138Z

Link: CVE-2025-62140

cve-icon Vulnrichment

Updated: 2025-12-31T17:33:19.047Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T14:15:53.363

Modified: 2026-04-23T15:34:36.980

Link: CVE-2025-62140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:15:17Z

Weaknesses