CVE-2025-52737
A vulnerability exists in WordPress plugins utilizing the Store Locator functionality. Specifically, versions 2.2.260 and below are susceptible due to a deserialization flaw that allows malicious input to be injected into PHP objects. This weakness can potentially enable attackers with contributor-level privileges or higher to inject arbitrary PHP code, which may result in unauthorized data retrieval, file deletion, or code execution if a vulnerability in another installed plugin or theme is exploited.
Based on public CVE data (MITRE/NVD).