Impact
The vulnerability allows attackers to inject arbitrary SQL through the store_locator_search_radius parameter, which is used in a numeric, unquoted context. Because WordPress’s wp_magic_quotes() addslashes protection cannot neutralize this payload, and the plugin’s AJAX handler performs no input sanitization, an attacker can append additional queries to the existing statement. This provides a direct path to read sensitive data from the database when accessed without authentication.
Affected Systems
WordPress sites that have WP Multi Store Locator Pro installed from the vendor wpexpertsio, in any version up to and including 4.5.1. The affected code resides in the public AJAX endpoint wp_ajax_nopriv_make_search_request and the store_locator_search_radius parameter used in the query.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is remote and does not require authentication or a valid nonce, an attacker can simply send a crafted HTTP request to the AJAX endpoint and gain privileged database access if the site’s database credentials are weak or exposed. The combination of high impact and low defensive checks results in a significant risk if the plugin is left at an affected version.
OpenCVE Enrichment