SQL Injection Vulnerability in Highwarden Super Store Finder
CVE-2025-52720

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-52720?

An SQL Injection vulnerability in Highwarden's Super Store Finder allows attackers to manipulate SQL queries and gain unauthorized access to sensitive data. This flaw arises from improper neutralization of special elements in SQL commands, affecting versions from n/a up to 7.5. Exploiting this vulnerability could lead to severe data breaches, making it essential for users to apply the necessary patches promptly.

Affected Version(s)

Super Store Finder <= 7.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.