CVE-2026-9062 PUBLISHED

Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal

Assigner: WPScan
Reserved: 20.05.2026 Published: 13.06.2026 Updated: 13.06.2026

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary .php files from the server, including configuration files that contain database credentials and authentication keys.

Product Status

Vendor Unknown
Product Store Locator WordPress
Versions Default: unaffected
  • affected from 0 to 1.6.9 (excl.)

Credits

  • Abisheik M finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE