High 8.5
2025-12-14< 1.6.3
Store Locator WordPress <= 1.6.2 - Authenticated (Contributor+) SQL Injection
Minimum safe version
1.6.3
Update to 1.6.3 or later to address 8 fixable vulnerabilities
Store Locator WordPress <= 1.6.2 - Authenticated (Contributor+) SQL Injection
CVE-2025-49329
CVE-2025-49328
WordPress Store Locator WordPress Plugin <= 1.4.14 is vulnerable to Arbitrary File Deletion
CVE-2023-4151
CVE-2023-27618
CVE-2022-4832
CVE-2022-41615