CVE-2026-15056Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-18: 3Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Full discourse3 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    # Falla en plugin de comercio electrónico para WordPress expone archivos sensibles del servidor CVE-2026-15056 permite a usuarios con permisos de vendedor leer contenido arbitrario del sistema mediante traversal de directorios en StoreEngine https://t.co/ApK2FcYo1p

    Post summary

    The tweet announces CVE-2026-15056, a directory traversal flaw in the WordPress StoreEngine plugin that lets vendor‑level users access arbitrary server files.

    121323.5K
    22.6K followersView on X
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    # Falla en plugin de comercio electrónico para WordPress expone archivos sensibles del servidor CVE-2026-15056 permite a usuarios con permisos de vendedor leer contenido arbitrario del sistema mediante traversal de directorios en StoreEngine.

    Post summary

    The text announces a directory traversal flaw in the WordPress StoreEngine plugin that allows vendor‑role users to read arbitrary server files, identified as CVE‑2026‑15056.

    10000141
    22.5K followersView on X
  • Ciberseguridad LATAM@CibersegLATAM
    General

    Una vulnerabilidad de severidad media catalogada como CVE-2026-15056 afecta a todas las versiones del plugin StoreEngine — Complete eCommerce Solution with Memberships,

    Post summary

    The statement merely announces a medium severity CVE affecting all versions of the StoreEngine plugin without providing additional details.

    10000157
    22.5K followersView on X

Explore more