PT-2026-49080 · WordPress · Store Locator
CVSS v3.1
3.4
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Store Locator WordPress plugin versions prior to 1.6.9
Description
Insufficient validation of a parameter used in a file path allows high-privileged users, such as administrators, to read arbitrary
.php files from the server. This can lead to the exposure of sensitive information, including configuration files containing authentication keys and database credentials.Recommendations
Update the plugin to version 1.6.9 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Store Locator