๐Ÿ” CVE Alert

CVE-2025-30919

UNKNOWN 0.0

WordPress Store Locator Widget plugin <= 2025r2 - CSRF to Stored XSS vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget store-locator-widget allows Stored XSS.This issue affects Store Locator Widget: from n/a through <= 2025r2.

CWE CWE-352
Vendor store locator widgets
Product store locator widget
Published Mar 27, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for store locator widgets store locator widget

Be the first to know when new unknown vulnerabilities affecting store locator widgets store locator widget are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Store Locator Widgets / Store Locator Widget
0 โ‰ค 2025r2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/store-locator-widget/vulnerability/wordpress-store-locator-widget-plugin-20200131-csrf-to-stored-xss-vulnerability?_s_id=cve

Credits

Abdi Pranata | Patchstack Bug Bounty Program