CVE-2026-9062: Unknown Store Locator WordPress
Low severity, CVSS 3.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
Affected products
- Unknown Store Locator WordPress: before 1.6.9 (fixed in 1.6.9)
Published 2026-06-13. Last modified 2026-07-21.