LOW
highwarden
CVE published 2026-10-11
CVE-2026-108541
A vulnerability was found in the Super Store Finder plugin up to version 3.8. An unknown function in the file /products/superstorefinder/index.php is affected by SQL injection through the manipulation of the lat and lng arguments. Remote exploitation is possible. The issue can be addressed by upgrading to version 3.9. Defenders should assess exposure and prioritize upgrading to version 3.9. The CVE record [truncated]