CVE-2026-9062
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
| Vendor | unknown |
| Product | store locator wordpress |
| Published | Jun 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown store locator wordpress
Be the first to know when new unknown vulnerabilities affecting unknown store locator wordpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Store Locator WordPress
0 < 1.6.9
References
Credits
Abisheik M WPScan