CyberRota Analysis
AI-GeneratedThe Super Store Finder plugin for WordPress versions up to 7.8 is vulnerable to SQL injection due to inadequate sanitization of an unauthenticated AJAX action parameter, enabling attackers to execute arbitrary SQL queries and potentially extract sensitive data from the database. Organizations using this plugin should prioritize immediate patching or removal to mitigate the risk of data breaches. This vulnerability poses a critical threat, particularly for sites handling sensitive user information.
Original NVD Description
The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.