CVE-2016-10939: Xtremelocator

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.

Affected products

Published 2019-09-13. Last modified 2026-06-17.