CVE-2024-11267

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:joomlaserviceprovider:jsp_store_locator:*:*:*:*:*:wordpress:*:*

History

12 Jun 2025, 16:58

Type Values Removed Values Added
CWE CWE-89
CPE cpe:2.3:a:joomlaserviceprovider:jsp_store_locator:*:*:*:*:*:wordpress:*:*
First Time Joomlaserviceprovider jsp Store Locator
Joomlaserviceprovider
References () https://wpscan.com/vulnerability/fcbdc11a-a194-46e4-8c22-11010b98fdab/ - () https://wpscan.com/vulnerability/fcbdc11a-a194-46e4-8c22-11010b98fdab/ - Exploit, Third Party Advisory

20 May 2025, 20:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/fcbdc11a-a194-46e4-8c22-11010b98fdab/ - () https://wpscan.com/vulnerability/fcbdc11a-a194-46e4-8c22-11010b98fdab/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento JSP Store Locator de WordPress hasta la versión 1.0 no depura ni escapa un parámetro antes de usarlo en una declaración SQL, lo que permite que los usuarios con Contributor realicen ataques de inyección SQL.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-12 16:58


NVD link : CVE-2024-11267

Mitre link : CVE-2024-11267

CVE.ORG link : CVE-2024-11267


JSON object : View

Products Affected

joomlaserviceprovider

  • jsp_store_locator
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')