Description
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection occurs in a numeric, unquoted SQL context, meaning WordPress's wp_magic_quotes() addslashes-based protection cannot neutralize the payload, and the AJAX handler is registered on wp_ajax_nopriv_make_search_request with no nonce or capability check, making it fully accessible without authentication.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated SQL Injection that can expose sensitive database data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows attackers to inject arbitrary SQL through the store_locator_search_radius parameter, which is used in a numeric, unquoted context. Because WordPress’s wp_magic_quotes() addslashes protection cannot neutralize this payload, and the plugin’s AJAX handler performs no input sanitization, an attacker can append additional queries to the existing statement. This provides a direct path to read sensitive data from the database when accessed without authentication.

Affected Systems

WordPress sites that have WP Multi Store Locator Pro installed from the vendor wpexpertsio, in any version up to and including 4.5.1. The affected code resides in the public AJAX endpoint wp_ajax_nopriv_make_search_request and the store_locator_search_radius parameter used in the query.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is remote and does not require authentication or a valid nonce, an attacker can simply send a crafted HTTP request to the AJAX endpoint and gain privileged database access if the site’s database credentials are weak or exposed. The combination of high impact and low defensive checks results in a significant risk if the plugin is left at an affected version.

Generated by OpenCVE AI on September 19, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Multi Store Locator Pro to version 4.6.0 or later to apply the vendor‑supplied fix.
  • If an upgrade is not immediately possible, remove or disable the public AJAX endpoint by modifying the plugin to require authentication, add a nonce verification, and properly escape or whitelist numerical input.
  • As a temporary safeguard, enable a web application firewall rule that detects and blocks suspicious query strings against the store_locator_search_radius parameter to prevent injection attempts.

Generated by OpenCVE AI on September 19, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpexperts
Wpexperts wp Multi Store Locator
Vendors & Products Wordpress
Wordpress wordpress
Wpexperts
Wpexperts wp Multi Store Locator

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection occurs in a numeric, unquoted SQL context, meaning WordPress's wp_magic_quotes() addslashes-based protection cannot neutralize the payload, and the AJAX handler is registered on wp_ajax_nopriv_make_search_request with no nonce or capability check, making it fully accessible without authentication.
Title WP Multi Store Locator Pro <= 4.5.1 - Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wpexperts Wp Multi Store Locator
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:51.421Z

Reserved: 2026-07-09T15:00:08.755Z

Link: CVE-2026-15275

cve-icon Vulnrichment

Updated: 2026-09-19T14:13:16.739Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:59.870

Modified: 2026-09-19T15:16:58.363

Link: CVE-2026-15275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')