Undefined · Undefined · CVE-2026-12965
**Name of the Vulnerable Software and Affected Versions**
Super Store Finder WordPress plugin versions prior to 7.11
**Description**
An unauthenticated AJAX action fails to sanitize a parameter before incorporating it into a SQL query. This allows unauthenticated attackers to execute SQL injection, a technique used to manipulate database queries, and extract sensitive data from the database.
**Recommendations**
Update Super Store Finder WordPress plugin to version 7.11 or later.