VendorsInstaWPstring_locatorany version
Vulnerabilities

InstaWP String Locator any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-2434
String Locator <= 2.5.0 - Cross-Site Request Forgery to PHAR Deserialization
Published 2022-09-06 · Modified
8.8EPSS 0.017
CVE-2024-10936
String Locator <= 2.6.6 - Unauthenticated PHP Object Injection
Published 2025-01-21 · Analyzed
8.8EPSS 0.011
CVE-2023-6987
String Locator <= 2.6.5 - Reflected Cross-Site Scripting
Published 2024-08-24 · Analyzed
6.1EPSS 0.003