CVE-2023-4151

CVE-2023-4151: Store Locator WordPress < 1.4.13 - Reflected XSS

Vendor Unknown
Product Store Locator WordPress
Published September 4, 2023
Last update March 6, 2025

CVSS base score

What the vulnerability does

01Description

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Key dates

02Disclosure timeline

September 4, 2023 CVE published
March 6, 2025 Record updated