CVE-2026-73392: WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Affected Software
1 affected component
WordPress Super Store Finder<=7.8
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are exposed?
Sites using Super Store Finder version 7.8 or earlier are affected. The issue is reachable over the network and requires no authentication or user interaction, so publicly accessible installations are the most exposed.
2
What does an attacker need to exploit this?
An attacker does not need an account or any user interaction to exploit the vulnerability. The provided severity vector indicates low attack complexity and potential high confidentiality impact, with a low availability impact.