PT-2026-67022 · Undefined · Undefined
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Super Store Finder WordPress plugin versions prior to 7.11
Description
An unauthenticated AJAX action fails to sanitize a parameter before incorporating it into a SQL query. This allows unauthenticated attackers to execute SQL injection, a technique used to manipulate database queries, and extract sensitive data from the database.
Recommendations
Update Super Store Finder WordPress plugin to version 7.11 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined