PatchSiren

Super Store Finder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Super Store Finder CVE published 2026-08-03

CVE-2026-12965

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. This vulnerability has a significant impact on the security of WordPress installations using the Super Store Finder plugin. Affected users should verify the vulnera [truncated]