What is CVE-2026-12965?
CVE-2026-12965 is a critical SQL injection vulnerability in the "Super Store Finder" WordPress plugin up to version 7.8. The flaw stems from an unsanitized parameter in an unauthenticated AJAX action, allowing remote attackers to extract sensitive data from the database. Immediate plugin update or temporary deactivation is strongly recommended.
Azərbaycanca: CVE-2026-12965, "Super Store Finder" WordPress plaginin 7.8 versiyasına qədər olan versiyalarında aşkar edilmiş kritik SQL injection boşluğudur. Zəiflik autentifikasiya olunmamış AJAX əməliyyatında parametrin sanitizasiya edilməməsi səbəbindən yaranır və uzaqdan hücumçulara məlumat bazasından həssas məlumatları oxumağa imkan verir. Plagin dərhal ən son versiyaya yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Through what type of action can CVE-2026-12965 be exploited?
The vulnerability is exploited through an unsanitized parameter in an unauthenticated AJAX action.
Which plugin is affected by CVE-2026-12965?
This vulnerability affects the "Super Store Finder" WordPress plugin up to version 7.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.