Executive brief
Locatoraid Store Locator is a WordPress plugin used to display store locations on websites. An unauthenticated SQL injection vulnerability in versions 3.9.72 and earlier allows attackers to read, modify, or delete the entire database without authentication, potentially exposing customer data, user credentials, and enabling complete site compromise.
Technical details
The plugin contains an unauthenticated SQL injection vulnerability in versions up to 3.9.72. This allows attackers to construct malicious SQL queries through the plugin's vulnerable endpoint without requiring authentication or user interaction. An attacker can read, modify, or delete the entire database including user accounts and private data. The vulnerability has been patched in version 3.9.73; affected sites should update immediately as this is a high-priority issue commonly used in mass-exploit campaigns.
Affected products
- Locatoraid Store Locator <= 3.9.72
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Patched in version 3.9.73