Impact
An application‑level flaw allows attackers to inject arbitrary SQL through unsanitized input, identified as CWE‑89. The flaw can be leveraged to read, modify, or delete sensitive data in the WordPress database, and may be used to elevate privileges if the database account has broad rights.
Affected Systems
The WordPress plugin Super Store Finder from highwarden is impacted when installed at version 7.2 or earlier, including all prior releases with no release number specified. Any site running those versions is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 signals a high severity. The EPSS score of <1% indicates that active exploitation is uncommon at present, and the vulnerability is not listed in CISA KEV. However, as the flaw permits direct execution of arbitrary SQL commands, the potential impact is severe. Although the description does not disclose authentication requirements, the attack vector likely involves sending crafted input to the plugin’s exposed endpoints, which could be accessible to authenticated users or potentially to unauthenticated visitors depending on the plugin configuration.
OpenCVE Enrichment
EUVD