← WordPress Vulnerabilities
WordPress security by component

String locator

String locator is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jan 21, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: string-locator

CVE-2024-10936: String locator: Code execution

String locator is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedJan 21, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 21, 2025 CVE-2024-10936
String locator: Code execution
String locator is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Aug 24, 2024 CVE-2023-6987
String locator: Cross-site scripting
String locator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 06, 2022 CVE-2022-2434
String Locator: Code execution
String Locator is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Mar 28, 2022 CVE-2022-0493
String locator: Filesystem traversal
String locator is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9