ZeroHour

CVE-2026-81768

moderate

Unauthenticated XSS in Super Store Finder WordPress plugin (through 7.10)

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

Super Store Finder, a WordPress plugin used to embed store-locator maps on websites, contains a cross-site scripting flaw (CWE-79) in versions up to and including 7.10. Because the issue is unauthenticated, an attacker does not need an account and can supply malicious input through the affected component that is then rendered in another user's browser. A successful attack executes attacker-controlled JavaScript in the context of the victim's session, which can be used to hijack an administrator's login, create rogue users, or alter content, matching the low confidentiality/integrity impact and scope change in the CVSS vector. Any WordPress site running Super Store Finder 7.10 or older is affected, with the most exposed being sites where store-locator pages are publicly reachable. There is no evidence of active exploitation, no public proof-of-concept, and the 30-day exploitation probability is estimated low (EPSS 0.1%).

What to do: Update Super Store Finder to a release newer than 7.10 as soon as the vendor publishes a patched version and confirm the fix in the plugin changelog. Until patched, deactivate the plugin on sites that do not require the store locator, and watch for unexpected administrator accounts or content changes, since unauthenticated XSS can be used to take over admin sessions.

Affected
Super Store Finder (superstorefinder.net) Super Store Finder WordPress plugin<= 7.10
Estimated exposure
moderateon the order of ~10,000 sites (free plugin has historically shown ~10k+ active installs on WordPress.org; premium/standalone deployments uncounted) — Based on the WordPress.org plugin directory's listed active-install count for the free version of Super Store Finder, with paid versions and standalone deployments not publicly tracked, so this is a floor estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.