SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12965

CRITICAL · CVSS 9.1 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Super Store Finder plugin for WordPress versions up to 7.8 is vulnerable to SQL injection due to inadequate sanitization of an unauthenticated AJAX action parameter, enabling attackers to execute arbitrary SQL queries and potentially extract sensitive data from the database. Organizations using this plugin should prioritize immediate patching or removal to mitigate the risk of data breaches. This vulnerability poses a critical threat, particularly for sites handling sensitive user information.

CVE
CVE-2026-12965
Severity
CRITICAL
CVSS
9.1
EPSS
0.35%
WordPress

Original NVD Description

The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.