Vulnerability Bulletins

CVE-2026-9062

   
Affected software WORDPRESS
 
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-9062