WordPress Ajax Store Locator 1.2 SQL Injection

WordPress Ajax Store Locator versions 1.2 and below suffer from a remote SQL injection vulnerability.