Low severity3.4NVD Advisory· Published Jun 13, 2026· Updated Jun 15, 2026
CVE-2026-9062
CVE-2026-9062
Description
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary .php files from the server, including configuration files that contain database credentials and authentication keys.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<1.6.9+ 1 more
- (no CPE)range: <1.6.9
- (no CPE)range: <1.6.9
Patches
Vulnerability mechanics
References
1News mentions
1- WordPress Plugin Ecosystem: 25 CVEs Disclosed in Two-Day Wave, Three CriticalVypr Intelligence · Jun 13, 2026