Unauthenticated SQL Injection (SQLi) vulnerability discovered by Eagle Eye in WordPress Super Store Finder premium plugin (versions <= 6.3).
Solution
Plugin vendor claims that vulnerability is patched in version 6.4. However, other sources like WPScan claim that there is still one SQL Injection vector left. We do not have access to the code of the plugin to verify it. Update the WordPress Super Store Finder premium plugin to the latest available version (at least 6.4).
Found a vulnerability that puts your sites at risk?