Impact
The Super Store Finder plugin for WordPress contains an unauthenticated SQL Injection vulnerability in versions 7.8 and earlier. This flaw allows an attacker to send crafted requests that are directly injected into database queries, giving the attacker the ability to execute arbitrary SQL commands. The consequences may include full disclosure of site data, modification or deletion of records, or compromise of the database server, thereby impacting confidentiality, integrity, and potentially availability of the website.
Affected Systems
The vulnerability affects the WordPress "Super Store Finder" plugin developed by Highwarden, specifically all releases up to and including version 7.8. Any WordPress site that has that plugin installed and in use without newer updates is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this as critical severity. The EPSS score is not available, but the unauthenticated nature indicates that an attacker can exploit the flaw from anywhere that can reach the site without credentials. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors include a malicious user submitting specially crafted data through exposed plugin endpoints or URLs. As no authentication is required, exploitation requires only network access to the WordPress site.
OpenCVE Enrichment