SQL Injection Vulnerability in highwarden Super Store Finder
CVE-2024-43976

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2024

What is CVE-2024-43976?

An SQL Injection vulnerability exists in the Super Store Finder plugin developed by highwarden, specifically affecting versions from n/a to 6.9.7. This vulnerability arises from the improper neutralization of special elements used in SQL commands, allowing attackers to execute arbitrary SQL code. As a result, unauthorized access to sensitive data may occur, potentially leading to data breaches and compromised system integrity. It is essential for users of this plugin to assess their system configurations and apply necessary security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Super Store Finder 0 <= 6.9.7

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.