CVE-2026-81768: WordPress Super Store Finder plugin <= 7.10 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Super Store Finder pluginto a version that resolves this vulnerability.Fixed in 7.11
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
What versions are affected?
Super Store Finder plugin versions 7.10 and earlier are affected according to the available data.
What is the potential impact?
The supplied severity vector indicates low potential impact to confidentiality, integrity, and availability, with scope changed. Successful exploitation could therefore affect a user’s browser session in a way that has limited impacts across those areas.