CVE-2026-15056
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory
CVSS
6.5
Medio
EPSS
0.8%
p54
KEV
—
Exploit Today
16
0-100
Publicado: 16 ago 2026 · Última mod.: 16 ago 2026 · CWE-22
Sin historial EPSS suficiente todavía.
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/api/vendors.php#L281
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/api/vendors.php#L37
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/role.php#L37
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/shortcode.php#L112
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L192
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L513
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L557
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/api/vendors.php#L281
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/api/vendors.php#L37
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/role.php#L37
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/shortcode.php#L112
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L192
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L513
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L557
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?reponame=&old=3628877%40storeengine&new=3628877%40storeengine
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/9a866dfd-2374-4a66-9dee-b8bda47d1cc7?source=cve
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-747988.7 ALT—
——0SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join without validating that id matches SiYuan's node-ID format. An authenticated MCP client can supply path traversal sequences in id to cause the kernel to copy an arbitrary file readable by the process into SiYuan's history directory (arbitrary file read) and then delete the original file (arbitrary file deletion). The corresponding HTTP API handler was hardened in GHSA-7hm9-v7vf-7g4w, but this MCP caller was not.52mCVE-2026-176044.9 MED53.7%
——16The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter parameter. This makes it possible for authenticated attackers, with editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The intended strpos()-based guard against leaving the uploads directory is bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences, such as /wp-content/uploads/../../wp-config.php.1dCVE-2026-145249.1 CRÍ50.2%
——15The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session with a path-traversal key, then call proSol_fileDeleteProcess with that key as the filename parameter; both steps require only the publicly exposed frontend nonce.1dCVE-2026-74764—33.7%
——10Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter.
An attacker able to submit a specially crafted TAR archive containing malicious member paths, such as paths using ../ sequences or absolute paths, could cause extracted files to be written outside the intended extraction directory. This may allow the attacker to overwrite files accessible to the Pandora worker process and could potentially result in application compromise, arbitrary code execution, or denial of service depending on the files targeted and the privileges of the Pandora process.
The vulnerability is corrected by using Python's filter='data' extraction filter, which rejects or sanitizes dangerous TAR members, including paths that escape the destination directory and unsafe link targets.
The weakness corresponds to MITRE's general path traversal category, which includes archive extraction cases where attacker-controlled filenames cause files to be written outside the intended directory.2dCVE-2026-188559.1 CRÍ65.7%
——20The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires the administrator to have enabled the 'Delete local file on link deletion' plugin option (disabled by default) and to subsequently permanently delete the attacker-submitted link, which is a routine moderation action.2dCVE-2026-144849.1 CRÍ52.3%
——16The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The nonce required to invoke the removal handler is exposed in public-facing JavaScript as RSMFCF7Vars.nonce on every Contact Form 7 page rendering a RapiSafe upload field, making it obtainable by any unauthenticated visitor.2d