CVE-2026-15056: StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parsefilepath function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15056?
CVE-2026-15056 has a severity rating of medium, specifically 6.5 on the CVSS scale.
How do I fix CVE-2026-15056?
To remediate CVE-2026-15056, update the StoreEngine plugin to version 2.1.2 or later.
Who is affected by CVE-2026-15056?
CVE-2026-15056 affects users of the StoreEngine plugin for WordPress up to and including version 2.1.1.
What type of vulnerability is CVE-2026-15056?
CVE-2026-15056 is a directory traversal vulnerability that allows authenticated attackers to perform arbitrary file reads.
What is the impact of CVE-2026-15056?
The impact of CVE-2026-15056 is that authenticated attackers can access sensitive files on the server.