WordPress Super Store Finder premium plugin <= 6.3 - Unauthenticated SQL Injection (SQLi) vulnerability

superstorefinder-wp

Software
Super Store Finder
Versions
<= 6.3
Disclosure date
2021-03-08
CVE
CVE-N/A
Credits
Classification
SQL Injection
OWASP Top 10
A1: Injection
CVSS 3.0 score

6.5

Medium

Can be exploited remotely without any authentication

Are your websites subject to this vulnerability?

Details

Unauthenticated SQL Injection (SQLi) vulnerability discovered by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.3).

Solution

Plugin vendor claims that vulnerability is patched in version 6.4. However, other sources like WPScan claim that there is still one SQL Injection vector left. We do not have access to the code of the plugin to verify it. Update the WordPress Super Store Finder premium plugin to the latest available version (at least 6.4).

Found a vulnerability that puts your sites at risk?

Found a vulnerability? Help us secure the web and join our community of ethical hackers.

Are you the developer of this software? Hire our researchers for a thorough security audit.