Impact
Unauthenticated Cross‑Site Scripting (XSS) exists in the Super Store Finder plugin for WordPress versions 7.10 and earlier. The flaw allows an attacker to inject malicious script into pages served to site visitors, leading to potential session hijacking, defacement, or redirection. The weakness is categorized as CWE‑79 – Improper Neutralization of Input During Web Page Generation.
Affected Systems
The vulnerability affects the Highwarden Super Store Finder plugin for WordPress. All installations running version 7.10 or earlier are susceptible. WordPress sites that rely on this plugin without upgrading are at risk. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity for this vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so exploitation activity is not currently tracked. Because the flaw is unauthenticated, any user with access to the plugin’s input fields can craft and publish malicious payloads, making exploitation straightforward once the attack vector exists.
OpenCVE Enrichment