CVE-2025-9215: StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Download
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the filedownload() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9215?
CVE-2025-9215 has a critical severity rating due to the risk of path traversal attacks.
How do I fix CVE-2025-9215?
To fix CVE-2025-9215, you should upgrade the StoreEngine WordPress eCommerce Plugin to version 1.5.1 or later.
Who is affected by CVE-2025-9215?
CVE-2025-9215 affects all versions of the StoreEngine WordPress eCommerce Plugin up to and including 1.5.0.
What type of vulnerability is CVE-2025-9215?
CVE-2025-9215 is a path traversal vulnerability that allows unauthorized file access.
Is authentication required to exploit CVE-2025-9215?
Yes, CVE-2025-9215 requires that an attacker is authenticated to exploit the vulnerability.