Themify Store Locator
Themify Store Locator has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Themify Store Locator has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. Themify Store Locator is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-12414Themify Store Locator <= 1.1.9 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Themify Store Locator
Author
themifyme
The Themify Store Locator plugin allows you to display an unlimited number of locations on a map, list, or grid view. Each store location can insert its own custom description, address, contact phone numbers, and business hours. All this information pops up on the map when users click on a map marker. Key Features: Unlimited Locations – Add unlimited locations with custom description, address, contact phone number, and business hours Store List Layouts – Display all locations in fullwidth, 4-column, 3-column, or 2-column layout Store Map – Display all locations on a Google map with a map tooltip that displays the location info Shortcode Generator – helps to generate location shortcodes without typing it manually
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C