PT-2026-49080 · Undefined · Undefined

Abisheik M

·

Published

2026-06-13

·

Updated

2026-06-13

·

CVE-2026-9062

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary .php files from the server, including configuration files that contain database credentials and authentication keys.

Exploit

Related Identifiers

CVE-2026-9062

Affected Products

Undefined