Executive brief
The Agile Store Locator plugin for WordPress, which helps businesses display physical locations on a map, contains a security flaw that allows administrative users to read sensitive server files. By exploiting this vulnerability, an attacker with high-level access could view the site's configuration files, potentially exposing database passwords and encryption keys. This could lead to a full compromise of the website's data and infrastructure.
Technical details
A path traversal vulnerability exists in the Agile Store Locator plugin for WordPress due to insufficient validation of the 'section' parameter in the 'reset_custom_template' and 'load_custom_template' AJAX handlers. An authenticated attacker with administrative privileges can provide a manipulated path (e.g., using '../' sequences) to read the contents of any .php file on the server. Because the application appends a '.php' extension to the input, the attack is limited to PHP files, but this includes critical files like 'wp-config.php' which contains database credentials and authentication salts. The issue is fixed in version 1.6.9.
Affected products
- AgileLogix Agile Store Locator < 1.6.9
Timeline
- 2026-05-23: disclosed: Vulnerability publicly published by WPScan
- 2026-06-13: advisory: CVE-2026-9062 published to NVD
- 2026-06-13: patched: Fixed in version 1.6.9