{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-multi-store-locator-pro--4.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_multi_store_locator_pro_project:wp_multi_store_locator_pro:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15275"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Multi Store Locator Pro (\u003c= 4.5.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe WP Multi Store Locator Pro plugin for WordPress (versions up to and including 4.5.1) contains a critical SQL injection vulnerability identified as CVE-2026-15275. The flaw exists within the 'store_locatore_search_radius' parameter handled by the 'wp_ajax_nopriv_make_search_request' AJAX handler. Because the handler is registered without nonce verification or user capability checks, the endpoint is accessible to unauthenticated remote attackers.\u003c/p\u003e\n\u003cp\u003eThe vulnerability arises because the plugin fails to properly prepare SQL queries or sanitize input before including it in database operations. Specifically, the injection occurs in a numeric, unquoted SQL context, which effectively bypasses WordPress's standard 'wp_magic_quotes()' addslashes-based protection. If exploited, an attacker can append malicious SQL commands to legitimate queries to exfiltrate sensitive data from the WordPress database. This represents a significant risk for organizations running this plugin on internet-facing WordPress instances.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to perform unauthorized SQL queries against the underlying database. This could result in the exfiltration of sensitive configuration data, user credentials, or administrative information contained within the WordPress database. The scope of impact is potentially any site utilizing versions 4.5.1 or older of the WP Multi Store Locator Pro plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WP Multi Store Locator Pro plugin to the latest available version beyond 4.5.1 to remediate CVE-2026-15275.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests directed at the WordPress AJAX endpoint related to the 'make_search_request' action.\u003c/li\u003e\n\u003cli\u003eReview database query logs or error logs for SQL syntax errors originating from non-authenticated users.\u003c/li\u003e\n\u003cli\u003eDisable the plugin immediately if an update is not currently available and the site is public-facing.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T10:05:12Z","date_published":"2026-09-18T10:05:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-multi-store-locator-sqli/","summary":"The WP Multi Store Locator Pro plugin for WordPress is vulnerable to unauthenticated SQL injection via the 'store_locatore_search_radius' parameter due to inadequate input sanitization and a lack of prepared statements.","title":"Unauthenticated SQL Injection in WP Multi Store Locator Pro","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-multi-store-locator-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Multi Store Locator Pro (\u003c= 4.5.1)","version":"https://jsonfeed.org/version/1.1"}