vendor:
Ajax Store Locator
by:
Claudio Viviani
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ajax Store Locator
Affected Version From: 1
Affected Version To: 1.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7, Linux
2015
WordPress Ajax Store Locator <= 1.2 SQL Injection Vulnerability
The 'sl_dal_searchlocation_cbf' ajax function in Wordpress Ajax Store Locator plugin version 1.2 and below is affected by a SQL Injection vulnerability. The 'StoreLocation' variable is not sanitized, allowing an attacker to inject malicious SQL queries.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input before using it in SQL queries. The plugin vendor should release a patch to address this issue.