Super Store Finder <= 7.8 - Unauthenticated SQL Injection
high
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.8. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...
- CVSS:
- 7.5
- Affected:
- up to 7.8
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-73392 on NVD →
Super Store Finder <= 7.8 - Unauthenticated SQL Injection
high
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...
- CVSS:
- 7.5
- Affected:
- up to 7.8
- Fix:
- No patched version reported
- Disclosed:
- Jul 24, 2026
CVE-2026-12965 on NVD →
Super Store Finder [superstorefinder-wp] <= 7.5 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
- Affected:
- up to 7.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2025
CVE-2025-58939 on NVD →
Super Store Finder [superstorefinder-wp] <= 6.9.7 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder. This issue affects Super Store Finder: from n/a through 6.9.7.
- Affected:
- up to 6.9.7
- Fix:
- No patched version reported
- Disclosed:
- Sep 9, 2025
CVE-2025-47571 on NVD →
Super Store Finder <= 7.6 - Reflected Cross-Site Scripting
medium
The Super Store Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 7.6
- Fixed in:
- 7.7
- Disclosed:
- Aug 21, 2025
Super Store Finder <= 7.5 - Cross-Site Request Forgery
medium
The Super Store Finder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 7.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2025
CVE-2025-58939 on NVD →
Super Store Finder [superstorefinder-wp] < 7.6
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection. This issue affects Super Store Finder: from n/a through 7.5.
- Affected:
- up to 7.6
- Fixed in:
- 7.6
- Disclosed:
- Aug 14, 2025
CVE-2025-52720 on NVD →
Super Store Finder <= 7.5 - Unauthenticated SQL Injection
high
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...
- CVSS:
- 7.5
- Affected:
- up to 7.5
- Fixed in:
- 7.6
- Disclosed:
- Jul 31, 2025
CVE-2025-52720 on NVD →
Super Store Finder < 6.8 - Unauthenticated Local File Inclusion
high
The Super Store Finder plugin for WordPress is vulnerable to Local File Inclusion in versions up to 7.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain se...
- CVSS:
- 8.1
- Affected:
- up to 7.8
- Fixed in:
- 7.8
- Disclosed:
- Jul 7, 2025
CVE-2025-47571 on NVD →
Super Store Finder [superstorefinder-wp] < 7.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 7.2.
- Affected:
- up to 7.5
- Fixed in:
- 7.5
- Disclosed:
- May 19, 2025
CVE-2025-39445 on NVD →
Super Store Finder <= 7.2 - Unauthenticated SQL Injection
high
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...
- CVSS:
- 7.5
- Affected:
- up to 7.2
- Fixed in:
- 7.5
- Disclosed:
- Apr 17, 2025
CVE-2025-39445 on NVD →
Super Store Finder [superstorefinder-wp] < 7.1
unknown
[en] The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentic...
- Affected:
- up to 7.1
- Fixed in:
- 7.1
- Disclosed:
- Feb 9, 2025
CVE-2024-13440 on NVD →
Super Store Finder <= 7.0 - Unauthenticated SQL Injection to Stored Cross-Site Scripting
high
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...
- CVSS:
- 8.2
- Affected:
- up to 7.0
- Fixed in:
- 7.1
- Disclosed:
- Feb 8, 2025
CVE-2024-13440 on NVD →
Super Store Finder [superstorefinder-wp] < 6.9.8
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a before 6.9.8.
- Affected:
- up to 6.9.8
- Fixed in:
- 6.9.8
- Disclosed:
- Sep 17, 2024
CVE-2024-43978 on NVD →
Super Store Finder [superstorefinder-wp] < 6.9.8
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 6.9.7.
- Affected:
- up to 6.9.8
- Fixed in:
- 6.9.8
- Disclosed:
- Sep 17, 2024
CVE-2024-43976 on NVD →
Super Store Finder [superstorefinder-wp] < 6.9.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in highwarden Super Store Finder allows Cross-Site Scripting (XSS).This issue affects Super Store Finder: from n/a through 6.9.7.
- Affected:
- up to 6.9.8
- Fixed in:
- 6.9.8
- Disclosed:
- Sep 17, 2024
CVE-2024-43975 on NVD →
Super Store Finder <= 6.9.7 - Unauthenticated SQL Injection
critical
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...
- CVSS:
- 10
- Affected:
- up to 6.9.7
- Fixed in:
- 6.9.8
- Disclosed:
- Aug 28, 2024
CVE-2024-43978 on NVD →
Super Store Finder <= 6.9.7 - Authenticated (Subscriber+) SQL Injection
critical
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access a...
- CVSS:
- 9.9
- Affected:
- up to 6.9.7
- Fixed in:
- 6.9.8
- Disclosed:
- Aug 28, 2024
CVE-2024-43976 on NVD →
Super Store Finder <= 6.9.7 - Unauthenticated Stored Cross-Site Scripting
high
The Super Store Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 7.2
- Affected:
- up to 6.9.7
- Fixed in:
- 6.9.8
- Disclosed:
- Aug 28, 2024
CVE-2024-43975 on NVD →
Super Store Finder [superstorefinder-wp] < 6.9.4
unknown
[en] The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails u...
- Affected:
- up to 6.9.4
- Fixed in:
- 6.9.4
- Disclosed:
- Sep 19, 2023
CVE-2023-5054 on NVD →
Super Store Finder <= 6.9.3 - Unauthenticated Email Creation/Sending
medium
The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utiliz...
- CVSS:
- 5.8
- Affected:
- up to 6.9.3
- Fixed in:
- 6.9.4
- Disclosed:
- Sep 18, 2023
CVE-2023-5054 on NVD →
Super Store Finder <= 6.4, Super Interactive Maps <= 2.1 - SQL Injection
critical
The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up to, and including 2.1 for WordPress are vulnerable to SQL Injection via the ‘ssf_wp_id’ parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- CVSS:
- 9.8
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Mar 8, 2021
Super Store Finder [superstorefinder-wp] < 6.5
unknown
The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up to, and including 2.1 for WordPress are vulnerable to SQL Injection via the ‘ssf_wp_id’ parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Mar 8, 2021
Super Store Finder [superstorefinder-wp] < 6.4
unknown
Unauthenticated SQL Injection (SQLi) vulnerability discovered by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.3).
- Affected:
- up to 6.4
- Fixed in:
- 6.4
- Disclosed:
- Mar 8, 2021
Super Store Finder <= 6.1, Super Interactive Maps <= 1.9, Super Logo Showcase <= 2.2 - Arbitrary File Upload
high
The Super Store Finder, Super Interactive Maps, and Super Logo Showcase plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation in the /pages/import.php file in versions up to, and including, 6.1, 1.9. and 2.2 respectively. This makes it possible for unauthenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 6.1
- Fixed in:
- 6.2
- Disclosed:
- Oct 21, 2020
Super Store Finder [superstorefinder-wp] < 6.2
unknown
Unauthenticated Arbitrary File Upload vulnerability found by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.1).
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Oct 21, 2020
Super Store Finder [superstorefinder-wp] < 6.2
unknown
The SuperStoreFinder premium WordPress plugins did not properly check file uploads, depending on the plugin, only checking for the mime type and/or the first extension of the file name.
An attacker could set the Content-Type header to "Content-Type: text/csv", as well as use a double extension to bypass th...
- Affected:
- up to 6.2
- Fixed in:
- 6.2
Super Store Finder [superstorefinder-wp] < 6.5
unknown
The ssf-social-action.php and sim-wp-data.php files from the respective superstorefinder-wp (<= 6.3) and super-interactive-maps (<= 2.1) plugins are effected by Multiple Unauthenticated SQL Injections, as they do not sanitise user data before using them in SQL statements.
superstorefinder-wp fixed most of the...
- Affected:
- up to 6.5
- Fixed in:
- 6.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database