Description
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
Published: 2026-08-31
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross‑Site Scripting (XSS) exists in the Super Store Finder plugin for WordPress versions 7.10 and earlier. The flaw allows an attacker to inject malicious script into pages served to site visitors, leading to potential session hijacking, defacement, or redirection. The weakness is categorized as CWE‑79 – Improper Neutralization of Input During Web Page Generation.

Affected Systems

The vulnerability affects the Highwarden Super Store Finder plugin for WordPress. All installations running version 7.10 or earlier are susceptible. WordPress sites that rely on this plugin without upgrading are at risk. No other products or versions are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity for this vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so exploitation activity is not currently tracked. Because the flaw is unauthenticated, any user with access to the plugin’s input fields can craft and publish malicious payloads, making exploitation straightforward once the attack vector exists.

Generated by OpenCVE AI on August 31, 2026 at 21:22 UTC.

Remediation

Vendor Solution

Update the WordPress Super Store Finder Plugin to the latest available version (at least 7.11).


OpenCVE Recommended Actions

  • Update the Super Store Finder plugin to version 7.11 or later, which removes the XSS vulnerability.
  • Clear any cached or persisted data that might contain malicious scripts inserted before the update.
  • If the plugin cannot be updated immediately, disable it or restrict access to its input features until a fix can be applied.

Generated by OpenCVE AI on August 31, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Highwarden
Highwarden super Store Finder
Wordpress
Wordpress wordpress
Vendors & Products Highwarden
Highwarden super Store Finder
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
Title WordPress Super Store Finder plugin <= 7.10 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Highwarden Super Store Finder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:35:50.326Z

Reserved: 2026-08-27T12:24:18.942Z

Link: CVE-2026-81768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:51.660

Modified: 2026-08-31T21:17:51.660

Link: CVE-2026-81768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')