Skip to content
ThreatCluster

Critical SQL Injection Vulnerability in JSP Store Locator Plugin

First seen 17 Apr 2026, 20:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 18, 2026 at 19:59 UTC
  • •CVE-2024-11267 is a critical SQL Injection vulnerability in the JSP Store Locator plugin.
  • •Exploitable by registered users with low privileges, allowing full database access.
  • •Immediate action is required: update or uninstall the affected plugin.

A critical SQL Injection vulnerability (CVE-2024-11267) has been identified in the JSP Store Locator WordPress plugin, rated CVSS 8.8. This vulnerability allows registered users with low privileges to execute SQL injection attacks without requiring victim interaction. Affected users can potentially read, modify, or delete all database data, leading to severe impacts on confidentiality, integrity, and availability. The vulnerability exists due to improper sanitization and escaping of parameters in SQL statements. Users of the plugin are urged to update or uninstall it immediately and to monitor database logs for any signs of exploitation. Continuous monitoring solutions for WordPress are recommended to mitigate future threats. The CVE was published on May 15, 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 173d ago How this analysis works

Timeline

2025-05-15
CVE-2024-11267 published
2026-04-17
Vulnerability reported in cybersecurity news articles

More articles in this cluster (2)

Following this threat?

Track CVE-2024-11267 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed