216.73.216.226

CVE-2026-9062

· Published 13/06/2026 09:16 · Modified 13/06/2026 07:16 · Author: The MITRE Corporation

Labels: CVE-2026-9062 2026-06-13CVE-2026-9062[email protected]

Essential information

Published
13/06/2026 09:16
Modified
13/06/2026 07:16
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
3.4 LOW (v3.1)
CISA KEV
No
CWE
CWE-22
EPSS (First)
P12.2% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00219)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

CVSS metrics

Description

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / store locator cpe:2.3:a:wordpress:store_locator:*:*:*:*:*:wordpress:*:*

References