Junglewise Threat Intelligence

CVE-2026-9062: Agile Store Locator arbitrary file read via path traversal

CVE-2026-9062 · Severity: info · CVSS 4.1 · Published 2026-06-13

Technologies: AgileLogix Agile Store Locator. Vendors: AgileLogix.

Executive brief

The Agile Store Locator plugin for WordPress, which helps businesses display physical locations on a map, contains a security flaw that allows administrative users to read sensitive server files. By exploiting this vulnerability, an attacker with high-level access could view the site's configuration files, potentially exposing database passwords and encryption keys. This could lead to a full compromise of the website's data and infrastructure.

Technical details

A path traversal vulnerability exists in the Agile Store Locator plugin for WordPress due to insufficient validation of the 'section' parameter in the 'reset_custom_template' and 'load_custom_template' AJAX handlers. An authenticated attacker with administrative privileges can provide a manipulated path (e.g., using '../' sequences) to read the contents of any .php file on the server. Because the application appends a '.php' extension to the input, the attack is limited to PHP files, but this includes critical files like 'wp-config.php' which contains database credentials and authentication salts. The issue is fixed in version 1.6.9.

Affected products

  • AgileLogix Agile Store Locator < 1.6.9

Timeline

  • 2026-05-23: disclosed: Vulnerability publicly published by WPScan
  • 2026-06-13: advisory: CVE-2026-9062 published to NVD
  • 2026-06-13: patched: Fixed in version 1.6.9

References

Related threats