Vulnerabilities > Store Locator Project > Store Locator > 2.3

DATE CVE VULNERABILITY TITLE RISK
2017-10-16 CVE-2014-8621 SQL Injection vulnerability in Store Locator Project Store Locator 2.3/3.11
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
network
low complexity
store-locator-project CWE-89
7.5