Review
Super Store Finder
CVE published 2026-08-03
CVE-2026-12965
The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. This vulnerability has a significant impact on the security of WordPress installations using the Super Store Finder plugin. Affected users should verify the vulnera [truncated]