Unauthenticated SQL Injection in Super Store Finder Plugin by WordPress
CVE-2026-73392
9.3CRITICAL
What is CVE-2026-73392?
The Super Store Finder plugin for WordPress versions up to 7.8 is susceptible to an unauthenticated SQL Injection vulnerability. This flaw allows attackers to execute arbitrary SQL queries through crafted input, potentially exposing sensitive data or compromising the database. It is crucial for users of this plugin to ensure they update to a patched version to mitigate the risk of exploitation.
Affected Version(s)
Super Store Finder <= 7.8