CVE-2025-47571
📛 CVE Title
WordPress Super Store Finder plugin < 7.8 - Local File Inclusion vulnerability
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.This issue affects Super Store Finder: from n/a through < 7.8.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- HIGH
- CVSS score
- 7.5 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Effective score
- 7.5 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-98 - Reserved
- 2025-05-07
- Published
- 2025-09-09 18:25 UTC
- Last updated
- 2026-04-28 18:12 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/47xxx/CVE-2025-47571.json
- Linked Threat
- CVE-2025-47571 — Super Store Finder < 6.8 - Unauthenticated Local File Inclusion
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-09-09 17:15:46 UTC
- NVD last modified
- 2026-06-17 09:28:20 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: audit@patchstack.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.6 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0043 (probability of exploitation in next 30 days)
- EPSS percentile
- 34.41% vs all CVEs — higher = more likely to be exploited, as of 2026-06-29
NVD / KEV / EPSS data refreshed 2026-06-30 10:44 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-27439 - Assigner
- Patchstack
- Published
- Sep 9, 2025, 4:25:27 PM
- Updated
- Apr 28, 2026, 4:12:45 PM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.4300
- Vendors
- highwarden
- Products
-
Super Store Finder (n/a ≤6.9.7)Super Store Finder (0 ≤7.8)
- Aliases
-
GHSA-7xq7-xhx6-47hr
ENISA description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.This issue affects Super Store Finder: from n/a through < 7.8.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| highwarden | Super Store Finder |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/98.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2025-47571 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-27439 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2025-47571 rapid7:www.cve.org
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5cd5d6f9-3011-4da8-a914-1e3e8075fdff?source=api-prod rapid7:www.wordfence.com
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
inclusion.this
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2025-47571
|
no local data | 2026-06-06 13:38 UTC |
Remediations (24)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.bandainamcoent.com
Patch 1.17 has been released for ELDEN RING. This patch aims to bring support the Tarnished Pack DLC, scheduled for release on Friday, August 28, 2026, and to implement gameplay balance adjustments.
2026-09-16 04:37 UTC -
web:crimsondesert.pearlabyss.com
Fellow Greymanes, Here are the fixes and improvements that have been added this patch . Major UpdatesThis patch adds various bug fixes and stability improvements. Update ScheduleThe patch is rolling out across all platforms. Please refer to the Update section below to see the state of the patch ...
2026-09-16 04:37 UTC -
web:docs.oracle.com
Oracle Security Critical Patch Update (CSPU) August 2026 for Oracle Java SE Services: Java Management Release Date: August 18, 2026
2026-09-16 04:37 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-09-16 04:37 UTC -
web:www.oracle.com
Oracle Critical Security Patch Update Advisory - August 2026 Description. A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, mor
2026-09-16 04:37 UTC -
web:lazyadmin.nl
In this article, we willl look at what caused the issue, which systems are affected, and how to fix it without stripping the September security patches. What is Happening The first reports appeared on Reddit's r/sysadmin shortly after the September updates rolled out. Multiple admins described the same failure pattern: RDS session hosts work normally after a reboot, then break a few hours ...
2026-09-16 04:37 UTC -
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-09-16 04:37 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - January 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical ...
2026-09-16 04:37 UTC -
Wordfence remediation: Super Store FinderWordfence
Update to version 7.8, or a newer patched version
2026-06-06 13:38 UTC -
web:www.lansweeper.com
The July 2025 edition of Patch Tuesday brings us 137 new fixes, with 14 rated as critical. We've listed the most important changes below. Microsoft SQL Server Remote Code Execution Vulnerability CVE - 2025 -49717, is a heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
2026-05-22 14:00 UTC -
web:isc.sans.edu
Macs are affected as well, but a patch is currently only available for Windows. CVE - 2025 -49719: This vulnerability has already been made public. It does allow for information disclosure on a Microsoft SQL Server. To patch , you must patch the OLE DB Driver. CVE - 2025 -49717: Exploitation is considered less likely for this vulnerability.
2026-05-22 14:00 UTC -
web:www.securityweek.com
Microsoft's August 2025 Patch Tuesday updates address critical vulnerabilities in Windows, Office, and Hyper-V.
2026-05-22 14:00 UTC -
web:www.bleepingcomputer.com
Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE - 2025 -53770 and CVE - 2025 -53771 that have compromised services worldwide in "ToolShell ...
2026-05-22 14:00 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-22 14:00 UTC -
web:www.maketecheasier.com
Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.
2026-05-22 02:50 UTC -
web:www.notebookcheck.net
Microsoft's February 2026 Windows 11 updates (KB5077181 and KB5075941) add security patches, bug fixes, and new Secure Boot rollout signals ahead of certificate expirations starting in June 2026.
2026-05-22 02:50 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 02:50 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 02:50 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 02:50 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-22 02:50 UTC -
web:source.android.com
Security patch levels of 2025 -11-01 or later address all of these issues. To learn how to check a device's security patch level, see Check and update your Android version. Within 48 hours after the initial publication of this bulletin, we will release the corresponding source code patches to the Android Open Source Project (AOSP) repository.
2026-05-22 02:50 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 02:50 UTC -
web:www.esri.com
Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.
2026-05-22 02:50 UTC -
web:www.ibm.com
This product is a minor release. After installing, your IBM SPSS Statistics product will be version 27.0.1.0.
2026-05-22 02:50 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-47571.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-47571",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-09T17:50:17.214718Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-09-09T18:41:51.519Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "superstorefinder-wp",
"product": "Super Store Finder",
"vendor": "highwarden",
"versions": [
{
"changes": [
{
"at": "7.8",
"status": "unaffected"
}
],
"lessThanOrEqual": "7.8",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Bonds | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:40:14.381Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.<p>This issue affects Super Store Finder: from n/a through < 7.8.</p>"
}
],
"value": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.This issue affects Super Store Finder: from n/a through < 7.8."
}
],
"impacts": [
{
"capecId": "CAPEC-252",
"descriptions": [
{
"lang": "en",
"value": "PHP Local File Inclusion"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:12:45.340Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/superstorefinder-wp/vulnerability/wordpress-super-store-finder-plugin-6-9-7-local-file-inclusion-vulnerability?_s_id=cve"
}
],
"title": "WordPress Super Store Finder plugin < 7.8 - Local File Inclusion vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2025-47571",
"datePublished": "2025-09-09T16:25:27.014Z",
"dateReserved": "2025-05-07T09:55:20.908Z",
"dateUpdated": "2026-04-28T16:12:45.340Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}