9.3
CVSSv3

CVE-2025-28898

CVSSv4: NA | CVSSv3: 9.3 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00043 | KEV: Not Included
Published: 26/03/2025 Updated: 26/03/2025

Vulnerability Summary

SQL Injection Vulnerability in WP Multistore Locator Plugin Before 2.5.2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Multistore Locator allows SQL Injection. This issue affects WP Multistore Locator: from n/a up to and including 2.5.2.

Vulnerable Product Search on Vulmon Subscribe to Product

notfound wp multistore locator