Description
WordPress Plugin Store Locator Plus for WordPress is prone to an open email relay vulnerability that lets attackers send mass emails without authentication. An attacker could exploit this issue to send unsolicited spam email to an unrestricted number of email addresses. WordPress Plugin Store Locator Plus for WordPress version 4.2.25 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.2.27 or latest
References
Related Vulnerabilities
WordPress Plugin Rucy Cross-Site Request Forgery (0.4.4)
Plone CMS CVE-2011-3587 Vulnerability (CVE-2011-3587)
OpenSSL DEPRECATED: Code Vulnerability (CVE-2015-0286)
WordPress Plugin JetWidgets For Elementor Multiple Cross-Site Scripting Vulnerabilities (1.0.8)
Atlassian Jira Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6619)