Impact
The flaw arises from improper neutralization of user input during web page rendering, enabling the Super Store Finder plugin to echo malicious script content back to the browser. When an attacker embeds crafted input into a URL or form that is processed by the plugin, the victim’s browser executes the script in the context of the affected WordPress site. This capability can lead to session hijacking, credential theft, defacement or redirection. Based on the description, it is inferred that authentication is not required to trigger the reflected XSS, although the CWE description does not explicitly state this requirement.
Affected Systems
The vulnerability affects the WordPress plugin Super Store Finder by Highwarden. All released versions through 7.6 are vulnerable. Any WordPress site that has installed the plugin from version n/a up to and including 7.6 is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% shows a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers could trigger the XSS by directing a victim to a crafted URL or form containing malicious script, requiring no authentication; based on the description, this lack of authentication requirement is inferred. Administrators should treat it as a priority for patching.
OpenCVE Enrichment
EUVD