CVE-2026-9062: Store Locator WordPress Plugin Path Traversal Allows Sensitive File Read
The Store Locator WordPress plugin versions before 1.6.9 contain a path traversal vulnerability that allows site administrators to read sensitive files from the server, such as PHP configuration files containing database credentials and authentication keys. The vulnerability requires an authenticated administrator account to exploit, limiting its immediate risk to insider threats or compromised admin accounts.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 3.4 LOW · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-22
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-13 / 2026-06-17
NVD description (verbatim)
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-9062 is a path traversal vulnerability (CWE-22) in the Store Locator WordPress plugin. The plugin fails to validate a user-supplied parameter before incorporating it into a file path operation, enabling arbitrary file read access. The CVSS v3.1 score is 3.4 (LOW), reflecting a network-accessible attack vector, low attack complexity, high privilege requirement, and user interaction necessity. The vulnerability results in confidentiality loss without integrity or availability impact.
Business impact
Exploitation could expose sensitive configuration data, including database credentials, WordPress security keys, and authentication tokens. For organizations relying on this plugin, a compromised administrator account—whether through phishing, credential reuse, or insider activity—becomes a vector for extracting infrastructure secrets that could enable lateral movement or persistent access. The actual business risk depends on how tightly access controls are enforced and whether configuration files are stored in web-accessible directories.
Affected systems
The Store Locator WordPress plugin is affected in all versions prior to 1.6.9. Any WordPress installation running an older version of this plugin with an administrator user is potentially at risk. Organizations should verify their current plugin version and deployment scope across their WordPress estate.
Exploitability
Exploitation requires high-privileged access (WordPress administrator role) and user interaction (likely a click or navigation action), significantly constraining real-world attack surface. The vulnerability is not trivial to weaponize without an existing admin foothold. However, once admin credentials are compromised—a common outcome of social engineering or credential stuffing—exploitation becomes straightforward and requires no advanced techniques.
Remediation
Update the Store Locator WordPress plugin to version 1.6.9 or later. Administrators should also review access logs for suspicious file read patterns, audit who holds administrator privileges, and consider enforcing strong password policies and multi-factor authentication for all admin accounts. In parallel, ensure database credentials and configuration files are not stored in or linked from web-accessible directories.
Patch guidance
Upgrade the Store Locator WordPress plugin to version 1.6.9 or later through the WordPress plugin management interface or by manual download from the official plugin repository. Test the update in a staging environment before deploying to production. Verify that the plugin continues to function with your site configuration after patching.
Detection guidance
Monitor access logs for administrator accounts reading unusual file paths, especially patterns consistent with directory traversal (e.g., requests with `../` sequences or absolute paths to sensitive files). WordPress security plugins and file integrity monitoring tools can flag unexpected file access by plugins. Inspect admin user activity logs for access to configuration pages or API endpoints that might indicate reconnaissance. Review web server logs for HTTP requests targeting the Store Locator plugin with suspicious parameters.
Why prioritize this
Although the CVSS score is LOW (3.4), this vulnerability warrants timely attention because it directly exposes secrets that could be leveraged for wider compromise. The requirement for admin access means it is not an immediate mass-exploitation vector, but the consequences of exposure are material. Prioritize patching based on your organization's control over admin account access and the sensitivity of what might be read from your server's configuration.
Risk score, explained
The CVSS 3.1 score of 3.4 reflects the attack vector (network-accessible), low complexity, high privilege requirement, user interaction requirement, and confidentiality impact. The score appropriately de-emphasizes this vulnerability for most organizations because the admin-only prerequisite is a significant gating factor. However, the LOW score should not be mistaken for 'low business risk'—disclosure of configuration secrets can have outsized impact relative to the numerical score.
Frequently asked questions
Who can exploit this vulnerability?
Only users with WordPress administrator privileges can exploit this vulnerability. This includes site owners, administrators, and any compromised or rogue admin account. It does not affect regular site users or unauthenticated visitors.
What files can an attacker read?
An attacker can read arbitrary PHP files from the server, including wp-config.php (which contains database credentials and security keys), theme configuration files, and other sensitive data stored on disk. The scope depends on the file permissions and the server's directory structure.
Is this vulnerability in the CISA KEV catalog?
No, this vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog as of the information available. There is no public evidence of active exploitation in the wild.
Can I mitigate this without updating?
While patching is the definitive fix, you can reduce risk by strictly limiting who has administrator access, enforcing multi-factor authentication on admin accounts, and monitoring access logs for suspicious activity. However, these are compensating controls and should not replace a timely update.
This analysis is provided for informational purposes and is based on the vulnerability description and CVSS metrics as of the publication and modification dates. Organizations should verify all patch availability and version information against the plugin's official repository and vendor advisories before deploying updates. Testing in a staging environment is strongly recommended. The assessment of business impact and exploitability is general in nature; actual risk will vary based on your organization's specific deployment, access controls, and security posture. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-10264LOWPath Traversal in lharries whatsapp-mcp 0.0.1
- CVE-2026-12211LOWIntelbras iNVU 7016 FT Path Traversal Vulnerability Analysis
- CVE-2026-45380LOWOff-by-One Path Traversal in bit7z Archive Extraction
- CVE-2026-47712LOWDulwich Path-Traversal Vulnerability in Patch File Generation
- CVE-2026-49497LOWGhidra Path Traversal in Debug Symbol Resolution
- CVE-2016-20076HIGHWordPress Simple-Backup 2.7.11 Unauthenticated File Access & Deletion Vulnerability
- CVE-2016-20081HIGHHB Audio Gallery Lite Path Traversal Vulnerability – Unauthenticated File Download
- CVE-2017-20248HIGHApptha Slider Gallery Path Traversal Vulnerability