StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL
medium
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to...
- CVSS:
- 6.5
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 15, 2026
CVE-2026-15056 on NVD →
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload
high
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attack...
- CVSS:
- 8.8
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.1
- Disclosed:
- Sep 16, 2025
CVE-2025-9216 on NVD →
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Download
medium
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. This makes it possible for authenticated attackers, with Subscriber-level access an...
- CVSS:
- 6.5
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.1
- Disclosed:
- Sep 16, 2025
CVE-2025-9215 on NVD →
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More [storeengine] < 1.5.1
unknown
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
CVE-2025-9216 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database