Skip to content

CVE-2024-11267 — Critical SQL Injection (CVSS 8.8)

Seckhmet • April 17, 2026

A high-severity SQL Injection (CVSS 8.8) was discovered in the WordPress plugin JSP Store Locator . This vulnerability is particularly dangerous because it is exploitable with low user privileges (PR:L) , without victim interaction, and results in a triple critical impact on confidentiality, integrity and availability .

Any registered user on a WordPress site using this plugin can potentially read, modify or delete all data in the database, or even take the site offline.

Immediately update or uninstall the JSP Store Locator plugin. Check database logs for any past exploitation. Deploy a continuous WordPress monitoring solution to anticipate this type of threat as soon as a CVE is published.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)