Security Advisory

CVE-2026-9062

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-13 06:00:01
Last updated 2026-06-15 14:48:05
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.