SQL Injection Vulnerability in Highwarden Super Store Finder
CVE-2024-43978

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2024

What is CVE-2024-43978?

An SQL Injection vulnerability exists in the Highwarden Super Store Finder plugin, where improper neutralization of special elements used in SQL commands can lead to unauthorized access to database content and manipulation. This vulnerability impacts Super Store Finder versions earlier than 6.9.8, creating a significant concern for users employing this software for their web applications.

Affected Version(s)

Super Store Finder 0 <= 6.9.8

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.