Description
Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
Published: 2025-10-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) in the highwarden Super Store Finder WordPress plugin allows an attacker to make authenticated requests on behalf of a logged‑in user. The flaw is present in all releases up to version 7.5 and permits the attacker to perform any action that is permitted by the victim’s WordPress role, potentially stealing data, publishing content, or changing settings. The weakness is identified as CWE‑352.

Affected Systems

All installations of the highwarden Super Store Finder plugin for WordPress with version 7.5 or earlier are vulnerable. The plugin is distributed under the highwarden namespace and is commonly used to provide store location search functionality. No other product families are mentioned.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑moderate severity. The EPSS score of < 1 % shows that the probability of exploitation is minimal at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to be authenticated to WordPress and to have the CSRF‑enabled form or endpoint accessed by the attacker’s site, so it is largely a “social‑engineering” style attack that depends on user interaction. The overall risk to servers is therefore limited but should not be ignored, especially on sites with high‑value content or administrative functions exposed through the plugin.

Generated by OpenCVE AI on April 29, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Super Store Finder to the latest version that removes the CSRF bug; if version 7.6 or later is available, apply it immediately.
  • If an update is not yet released, remove the plugin from production sites or deactivate the store‑finding component until a patch is available.
  • As a temporary workaround, restrict access to any plugin URLs that accept state‑changing requests to authenticated administrators only, and add an administrator‑only request‑nonce check where possible.

Generated by OpenCVE AI on April 29, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
Title WordPress Super Store Finder plugin <= 7.5 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:50.006Z

Reserved: 2025-09-06T04:44:48.015Z

Link: CVE-2025-58939

cve-icon Vulnrichment

Updated: 2025-10-29T13:46:29.777Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:37.903

Modified: 2026-04-27T20:16:20.890

Link: CVE-2025-58939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses