CVE-2024-11267Disclosure(joomlaserviceprovider / jsp_store_locator)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsp_store_locator

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
jsp_store_locator

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-17: 1Technical Details · 2026-04-17: 104-17
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical SQL injection flaw CVE-2024-11267 in JSP Store Locator WordPress plugin lets low privilege users read, modify, delete full database data, CVSS 8.8. https://threatcluster.io/cluster/critical-sql-injection-vulnerability-in-jsp-store-locator-pl-fc2b2dc8

    Post summary

    A new critical SQL injection vulnerability CVE-2024-11267 affecting the JSP Store Locator WordPress plugin has been disclosed, allowing low‑privilege users to read, modify, and delete entire database data; no PoC, exploit, patch, or active exploitation details are provided.

    00000198
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlaserviceproviderjsp_store_locator-wordpress-

Explore more