CVE · High

CVE-2025-52737 — WP Store Locator [wp-store-locator] < 2.2.261

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-52737 WP Store Locator [wp-store-locator] < 2.2.261 Deserialization of Untrusted Data High 8.8 < 2.2.261 2.2.261 2025-07-31

CVE-2025-52737

A vulnerability exists in WordPress plugins utilizing the Store Locator functionality. Specifically, versions 2.2.260 and below are susceptible due to a deserialization flaw that allows malicious input to be injected into PHP objects. This weakness can potentially enable attackers with contributor-level privileges or higher to inject arbitrary PHP code, which may result in unauthorized data retrieval, file deletion, or code execution if a vulnerability in another installed plugin or theme is exploited.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.