Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin Store Locator Plus for WordPress Open Email Relay (4.2.25) - Vulnerability Database

WordPress Plugin Store Locator Plus for WordPress Open Email Relay (4.2.25)

Description

WordPress Plugin Store Locator Plus for WordPress is prone to an open email relay vulnerability that lets attackers send mass emails without authentication. An attacker could exploit this issue to send unsolicited spam email to an unrestricted number of email addresses. WordPress Plugin Store Locator Plus for WordPress version 4.2.25 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 4.2.27 or latest