PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108541 highwarden CVE debrief

A vulnerability was found in the Super Store Finder plugin up to version 3.8. An unknown function in the file /products/superstorefinder/index.php is affected by SQL injection through the manipulation of the lat and lng arguments. Remote exploitation is possible. The issue can be addressed by upgrading to version 3.9. Defenders should assess exposure and prioritize upgrading to version 3.9. The CVE record and NVD detail page provide information on the vulnerability, but the extent of exploitation and affected deployments require further verification.

Vendor
highwarden
Product
Super Store Finder
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for deploying and maintaining the Super Store Finder plugin should assess exposure and prioritize upgrading to version 3.9. They should also verify inventory of affected deployments, monitor for potential exploitation attempts, and review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-108541 is a SQL injection vulnerability in Super Store Finder that allows remote exploitation. Defenders should prioritize upgrading to version 3.9 and verify exposure of affected deployments.

  • Verify exposure of Super Store Finder deployments to SQL injection attacks
  • Assess priority for upgrading to version 3.9
  • Monitor for potential exploitation attempts
  • Verify inventory of affected deployments

Technical summary

The Super Store Finder plugin up to version 3.8 has a SQL injection vulnerability in an unknown function of the file /products/superstorefinder/index.php. The vulnerability is caused by the manipulation of the lat and lng arguments. The exploit has been disclosed to the public and may be used. Upgrading to version 3.9 is able to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Defensive priority

Defenders should prioritize upgrading to version 3.9 to address the SQL injection vulnerability in Super Store Finder.

Recommended defensive actions

  • Upgrade to version 3.9 of Super Store Finder to address the SQL injection vulnerability
  • Review and verify inventory of affected deployments
  • Monitor for potential exploitation attempts
  • Verify exposure of Super Store Finder deployments to SQL injection attacks
  • Assess priority for upgrading to version 3.9
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, but the extent of exploitation and affected deployments require further verification. Defenders should verify exposure of affected deployments and monitor for potential exploitation attempts. The vendor was contacted early and responded in a professional manner, quickly releasing a fixed version of the affected product.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108541 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108541

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108541 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108541

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.