CVE-2026-12965 PUBLISHED

Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking

Assigner: WPScan
Reserved: 23.06.2026 Published: 03.08.2026 Updated: 03.08.2026

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.

Product Status

Vendor Unknown
Product Super Store Finder WordPress
Versions Default: unknown
  • affected from 0 to 7.8 (incl.)

Credits

  • Michael Bielenberg finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE