CVE-2026-9062 Details
Description
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
A path traversal vulnerability has been identified in the Store Locator WordPress plugin, affecting versions prior to 1.6.9. The vulnerability arises because the plugin does not properly validate a parameter before using it in a file path. This flaw enables high-privileged users, such as administrators, to read arbitrary .php files from the server. Exploitation of this vulnerability could lead to the disclosure of sensitive information, including configuration files that contain database credentials and authentication keys.
Users are advised to update the Store Locator WordPress plugin to version 1.6.9 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 13, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/14014b6b-ce49-4778-822c-026ecafa1772/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Agile Store Locator | < 1.6.9 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 13, 2026 | New CVE Received | [email protected] |
Volerion