Junglewise Threat Intelligence

CVE-2026-81768: Super Store Finder cross-site scripting in WordPress plugin

CVE-2026-81768 · Severity: high · CVSS 7.1 · Published 2026-08-31

Executive brief

Super Store Finder is a WordPress plugin that helps businesses display store locations on their websites. An unauthenticated attacker can inject malicious scripts into the plugin that execute in visitors' browsers, potentially stealing customer data, hijacking accounts, or redirecting users to fraudulent sites. The vulnerability affects all versions up to 7.10 and has been patched in version 7.11.

Technical details

This is a Stored or Reflected Cross-Site Scripting (XSS) vulnerability in the Super Store Finder WordPress plugin that allows unauthenticated attackers to inject malicious JavaScript code. The vulnerability exists in versions 7.10 and earlier, with the root cause stemming from insufficient input validation or output encoding of user-controllable parameters. Exploitation requires user interaction—a victim must click a malicious link or visit a crafted page that triggers the XSS payload. Successful exploitation allows an attacker to steal session cookies, perform actions on behalf of the victim, deface the website, or harvest sensitive visitor data. Version 7.11 contains the fix; administrators should update immediately as Patchstack has issued a mitigation rule for those unable to patch.

Affected products

  • Super Store Finder Super Store Finder <=7.10

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Version 7.11 patched

References