
BREAKING: Critical SQL injection flaw CVE-2024-11267 in JSP Store Locator WordPress plugin lets low privilege users read, modify, delete full database data, CVSS 8.8. https://threatcluster.io/cluster/critical-sql-injection-vulnerability-in-jsp-store-locator-pl-fc2b2dc8
Post summary
A new critical SQL injection vulnerability CVE-2024-11267 affecting the JSP Store Locator WordPress plugin has been disclosed, allowing low‑privilege users to read, modify, and delete entire database data; no PoC, exploit, patch, or active exploitation details are provided.
