CVE-2026-12965
Received Received - Intake

SQL Injection in Super Store Finder WordPress Plugin

Vulnerability report for CVE-2026-12965, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
super_store_finder super_store_finder to 7.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Super Store Finder WordPress plugin version 7.8 or earlier. It allows unauthenticated attackers to inject malicious SQL code through an unauthenticated AJAX action parameter. This can lead to unauthorized database access and data extraction.

Detection Guidance

To detect this vulnerability, check if the Super Store Finder WordPress plugin version 7.8 or below is installed. Look for unauthenticated AJAX requests to the affected parameter in the plugin. Use network monitoring tools to inspect SQL query patterns or errors in logs that may indicate SQL injection attempts.

Impact Analysis

If you use this WordPress plugin, attackers could steal sensitive data from your database, such as customer information or login credentials. They could also manipulate or delete data, potentially disrupting your website's functionality.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection. Organizations may face legal penalties, fines, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Immediately update the Super Store Finder plugin to the latest version beyond 7.8. If an update is unavailable, consider disabling or removing the plugin. Implement web application firewalls to block malicious SQL injection attempts and monitor database queries for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12965. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart