BUGFLARE
Threat intelligence and bug bounty research platform. Live vulnerability data, in-app writeup reading, and program tracking — aggregated from trusted public sources.
© 2026 Bugflare. Publishers retain authorship; always verify on the source.
bugflare.site
CVE-2026-15056 · MEDIUM · Bugflare
CVE-2026-15056 MEDIUM CVE: CVE-2026-15056 - The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Direct... Sign in to save EPSS
N/A
Exploit Prediction Score
Exploitability
No EPSS data available
Description The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Packages No package data available.
Related references Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).
https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/api/vendors.php#L281 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/api/vendors.php#L37 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/role.php#L37 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/addons/multi-vendor/shortcode.php#L112 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L192 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L513 https://plugins.trac.wordpress.org/browser/storeengine/tags/1.10.0/includes/classes/download-handler.php#L557 https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/api/vendors.php#L281 https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/api/vendors.php#L37 https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/role.php#L37 Source
Originally published by NVD (nvd.nist.gov) .
CVE metadata is aggregated from public vulnerability databases. Scores and descriptions remain attributed to their origin feeds.
https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/addons/multi-vendor/shortcode.php#L112
https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L192
https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L513
https://plugins.trac.wordpress.org/browser/storeengine/tags/2.0.0/includes/classes/download-handler.php#L557
https://plugins.trac.wordpress.org/changeset?reponame=&old=3628877%40storeengine&new=3628877%40storeengine
https://www.wordfence.com/threat-intel/vulnerabilities/id/9a866dfd-2374-4a66-9dee-b8bda47d1cc7?source=cve