The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kodezen
Kodezen storeengine — Complete Ecommerce Solution With Memberships, Licensing, Affiliates & More Wordpress Wordpress wordpress |
|
| Vendors & Products |
Kodezen
Kodezen storeengine — Complete Ecommerce Solution With Memberships, Licensing, Affiliates & More Wordpress Wordpress wordpress |
Sun, 16 Aug 2026 05:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-08-16T05:27:29.669Z
Updated: 2026-08-17T16:05:27.770Z
Reserved: 2026-07-08T13:39:34.816Z
Link: CVE-2026-15056
Updated: 2026-08-17T14:14:12.707Z
Status : Received
Published: 2026-08-16T06:16:50.340
Modified: 2026-08-17T16:16:48.693
Link: CVE-2026-15056
No data.