plugin

Superstorefinder Wp Vulnerabilities

28 known security issues reported for the Superstorefinder Wp WordPress plugin. Most recent disclosed Aug 18, 2026.

3 critical 8 high 3 medium

Running Superstorefinder Wp on your site? Check whether your installed version is affected.

Scan your site free

Super Store Finder <= 7.8 - Unauthenticated SQL Injection

high

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.8. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
7.5
Affected:
up to 7.8
Fix:
No patched version reported
Disclosed:
Aug 18, 2026

CVE-2026-73392 on NVD →

Super Store Finder <= 7.8 - Unauthenticated SQL Injection

high

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
7.5
Affected:
up to 7.8
Fix:
No patched version reported
Disclosed:
Jul 24, 2026

CVE-2026-12965 on NVD →

Super Store Finder [superstorefinder-wp] <= 7.5 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.

Affected:
up to 7.5
Fix:
No patched version reported
Disclosed:
Oct 29, 2025

CVE-2025-58939 on NVD →

Super Store Finder [superstorefinder-wp] <= 6.9.7 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder. This issue affects Super Store Finder: from n/a through 6.9.7.

Affected:
up to 6.9.7
Fix:
No patched version reported
Disclosed:
Sep 9, 2025

CVE-2025-47571 on NVD →

Super Store Finder <= 7.6 - Reflected Cross-Site Scripting

medium

The Super Store Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 7.6
Fixed in:
7.7
Disclosed:
Aug 21, 2025

Super Store Finder <= 7.5 - Cross-Site Request Forgery

medium

The Super Store Finder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 7.5
Fix:
No patched version reported
Disclosed:
Aug 21, 2025

CVE-2025-58939 on NVD →

Super Store Finder [superstorefinder-wp] < 7.6

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection. This issue affects Super Store Finder: from n/a through 7.5.

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Aug 14, 2025

CVE-2025-52720 on NVD →

Super Store Finder <= 7.5 - Unauthenticated SQL Injection

high

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...

CVSS:
7.5
Affected:
up to 7.5
Fixed in:
7.6
Disclosed:
Jul 31, 2025

CVE-2025-52720 on NVD →

Super Store Finder < 6.8 - Unauthenticated Local File Inclusion

high

The Super Store Finder plugin for WordPress is vulnerable to Local File Inclusion in versions up to 7.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain se...

CVSS:
8.1
Affected:
up to 7.8
Fixed in:
7.8
Disclosed:
Jul 7, 2025

CVE-2025-47571 on NVD →

Super Store Finder [superstorefinder-wp] < 7.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 7.2.

Affected:
up to 7.5
Fixed in:
7.5
Disclosed:
May 19, 2025

CVE-2025-39445 on NVD →

Super Store Finder <= 7.2 - Unauthenticated SQL Injection

high

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...

CVSS:
7.5
Affected:
up to 7.2
Fixed in:
7.5
Disclosed:
Apr 17, 2025

CVE-2025-39445 on NVD →

Super Store Finder [superstorefinder-wp] < 7.1

unknown

[en] The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentic...

Affected:
up to 7.1
Fixed in:
7.1
Disclosed:
Feb 9, 2025

CVE-2024-13440 on NVD →

Super Store Finder <= 7.0 - Unauthenticated SQL Injection to Stored Cross-Site Scripting

high

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
8.2
Affected:
up to 7.0
Fixed in:
7.1
Disclosed:
Feb 8, 2025

CVE-2024-13440 on NVD →

Super Store Finder [superstorefinder-wp] < 6.9.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a before 6.9.8.

Affected:
up to 6.9.8
Fixed in:
6.9.8
Disclosed:
Sep 17, 2024

CVE-2024-43978 on NVD →

Super Store Finder [superstorefinder-wp] < 6.9.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 6.9.7.

Affected:
up to 6.9.8
Fixed in:
6.9.8
Disclosed:
Sep 17, 2024

CVE-2024-43976 on NVD →

Super Store Finder [superstorefinder-wp] < 6.9.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in highwarden Super Store Finder allows Cross-Site Scripting (XSS).This issue affects Super Store Finder: from n/a through 6.9.7.

Affected:
up to 6.9.8
Fixed in:
6.9.8
Disclosed:
Sep 17, 2024

CVE-2024-43975 on NVD →

Super Store Finder <= 6.9.7 - Unauthenticated SQL Injection

critical

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...

CVSS:
10
Affected:
up to 6.9.7
Fixed in:
6.9.8
Disclosed:
Aug 28, 2024

CVE-2024-43978 on NVD →

Super Store Finder <= 6.9.7 - Authenticated (Subscriber+) SQL Injection

critical

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access a...

CVSS:
9.9
Affected:
up to 6.9.7
Fixed in:
6.9.8
Disclosed:
Aug 28, 2024

CVE-2024-43976 on NVD →

Super Store Finder <= 6.9.7 - Unauthenticated Stored Cross-Site Scripting

high

The Super Store Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 6.9.7
Fixed in:
6.9.8
Disclosed:
Aug 28, 2024

CVE-2024-43975 on NVD →

Super Store Finder [superstorefinder-wp] < 6.9.4

unknown

[en] The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails u...

Affected:
up to 6.9.4
Fixed in:
6.9.4
Disclosed:
Sep 19, 2023

CVE-2023-5054 on NVD →

Super Store Finder <= 6.9.3 - Unauthenticated Email Creation/Sending

medium

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utiliz...

CVSS:
5.8
Affected:
up to 6.9.3
Fixed in:
6.9.4
Disclosed:
Sep 18, 2023

CVE-2023-5054 on NVD →

Super Store Finder <= 6.4, Super Interactive Maps <= 2.1 - SQL Injection

critical

The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up to, and including 2.1 for WordPress are vulnerable to SQL Injection via the ‘ssf_wp_id’ parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

CVSS:
9.8
Affected:
up to 6.5
Fixed in:
6.5
Disclosed:
Mar 8, 2021

Super Store Finder [superstorefinder-wp] < 6.5

unknown

The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up to, and including 2.1 for WordPress are vulnerable to SQL Injection via the ‘ssf_wp_id’ parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

Affected:
up to 6.5
Fixed in:
6.5
Disclosed:
Mar 8, 2021

Super Store Finder [superstorefinder-wp] < 6.4

unknown

Unauthenticated SQL Injection (SQLi) vulnerability discovered by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.3).

Affected:
up to 6.4
Fixed in:
6.4
Disclosed:
Mar 8, 2021

Super Store Finder <= 6.1, Super Interactive Maps <= 1.9, Super Logo Showcase <= 2.2 - Arbitrary File Upload

high

The Super Store Finder, Super Interactive Maps, and Super Logo Showcase plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation in the /pages/import.php file in versions up to, and including, 6.1, 1.9. and 2.2 respectively. This makes it possible for unauthenticated attackers...

CVSS:
8.8
Affected:
up to 6.1
Fixed in:
6.2
Disclosed:
Oct 21, 2020

Super Store Finder [superstorefinder-wp] < 6.2

unknown

Unauthenticated Arbitrary File Upload vulnerability found by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.1).

Affected:
up to 6.2
Fixed in:
6.2
Disclosed:
Oct 21, 2020

Super Store Finder [superstorefinder-wp] < 6.2

unknown

The SuperStoreFinder premium WordPress plugins did not properly check file uploads, depending on the plugin, only checking for the mime type and/or the first extension of the file name. An attacker could set the Content-Type header to &quot;Content-Type: text/csv&quot;, as well as use a double extension to bypass th...

Affected:
up to 6.2
Fixed in:
6.2

Super Store Finder [superstorefinder-wp] < 6.5

unknown

The ssf-social-action.php and sim-wp-data.php files from the respective superstorefinder-wp (&lt;= 6.3) and super-interactive-maps (&lt;= 2.1) plugins are effected by Multiple Unauthenticated SQL Injections, as they do not sanitise user data before using them in SQL statements. superstorefinder-wp fixed most of the...

Affected:
up to 6.5
Fixed in:
6.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database