CVE-2026-81768
moderateUnauthenticated XSS in Super Store Finder WordPress plugin (through 7.10)
Super Store Finder, a WordPress plugin used to embed store-locator maps on websites, contains a cross-site scripting flaw (CWE-79) in versions up to and including 7.10. Because the issue is unauthenticated, an attacker does not need an account and can supply malicious input through the affected component that is then rendered in another user's browser. A successful attack executes attacker-controlled JavaScript in the context of the victim's session, which can be used to hijack an administrator's login, create rogue users, or alter content, matching the low confidentiality/integrity impact and scope change in the CVSS vector. Any WordPress site running Super Store Finder 7.10 or older is affected, with the most exposed being sites where store-locator pages are publicly reachable. There is no evidence of active exploitation, no public proof-of-concept, and the 30-day exploitation probability is estimated low (EPSS 0.1%).
What to do: Update Super Store Finder to a release newer than 7.10 as soon as the vendor publishes a patched version and confirm the fix in the plugin changelog. Until patched, deactivate the plugin on sites that do not require the store locator, and watch for unexpected administrator accounts or content changes, since unauthenticated XSS can be used to take over admin sessions.
| Super Store Finder (superstorefinder.net) Super Store Finder WordPress plugin | <= 7.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.