Privilege Escalation Vulnerability in Store Locator Plus for WordPress Plugin

Privilege Escalation Vulnerability in Store Locator Plus for WordPress Plugin

CVE-2021-24289 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

Learn more about our Wordpress Pen Testing.