Description
WordPress Plugin Store Locator Plus for WordPress is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Store Locator Plus for WordPress version 5.5.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.7 or latest
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop Cookie Multiple SQL Injection Vulnerabilities (2.4.7)
MySQL CVE-2020-2679 Vulnerability (CVE-2020-2679)
Beego Framework Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2019-16354)
WordPress Plugin Browsealoud Crypto Mining (1.4)
WordPress 4.8.x Possible SQL Injection Vulnerability (4.8 - 4.8.2)