Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
https://superstorefinder.net/support/forums/topic/super-store-finder-patch-notes/