Access violation vulnerability in AJAX Store Locator 1.2

The Ajax Store Locator plugin for WordPress is vulnerable to an attack in which unauthorized users can download any file from the service. This is an issue in versions 1.2 and lower, because of the ‘download_file’ parameter found in the ‘sl_file_download.php’ file.

Detected in:

AJAX Store Locator open vulnerable versions: >= * <= 1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.