📦 Super Store Finder

by Superstorefinder

🔍 What is Super Store Finder?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-43976

CRITICAL CVSS 9.3 Sep 17, 2024

This SQL injection vulnerability in the Super Store Finder WordPress plugin allows attackers to execute arbitrary SQL commands on the database. All WordPress sites running Super Store Finder versions ...

CVE-2024-43978

CRITICAL CVSS 9.3 Sep 17, 2024

This SQL injection vulnerability in the Super Store Finder WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all WordPress sites running Super Store Finde...

CVE-2023-41507

CRITICAL CVSS 9.8 Sep 5, 2023

Super Store Finder v3.6 contains SQL injection vulnerabilities in its store locator component that allow attackers to execute arbitrary SQL commands via the products, distance, lat, and lng parameters...

CVE-2023-41508

CRITICAL CVSS 9.8 Sep 5, 2023

CVE-2023-41508 is a hard-coded credential vulnerability in Super Store Finder v3.6 that allows attackers to bypass authentication and gain administrative access to the application's administration pan...

CVE-2024-13440

HIGH CVSS 8.2 Feb 9, 2025

The Super Store Finder WordPress plugin contains an SQL injection vulnerability in the 'ssf_wp_user_name' parameter that allows unauthenticated attackers to inject malicious SQL queries. This can lead...

CVE-2024-43975

HIGH CVSS 7.1 Sep 18, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in the WordPress Super Store Finder plugin. Attackers can inject malicious scripts into web pages generated by the plugin, potentially com...

CVE-2023-43835

HIGH CVSS 8.8 Oct 2, 2023

This vulnerability allows authenticated attackers to inject arbitrary PHP code into the config.inc.php file of Super Store Finder, leading to remote code execution. It affects Super Store Finder versi...

CVE-2023-44044

HIGH CVSS 7.2 Sep 27, 2023

Super Store Finder v3.6 and earlier contains a SQL injection vulnerability in the admin interface's search functionality. Attackers can exploit this to execute arbitrary SQL commands on the database. ...