CVE-2021-24290
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
Date published : 2021-05-17
https://wpscan.com/vulnerability/dc368484-f2fe-4c76-ba3d-e00e7f633719
Severe Unpatched Vulnerabilities Leads to Closure of Store Locator Plus Plugin