| Summary | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys. |
|---|---|
| Publication Date | June 13, 2026, 4:16 p.m. |
| Registration Date | June 14, 2026, 4:11 a.m. |
| Last Update | June 13, 2026, 4:16 p.m. |