What is CVE-2026-15056?
A Directory Traversal vulnerability has been discovered in the StoreEngine WordPress plugin via the 'parse_file_path' function, affecting all versions up to 2.1.1. Authenticated attackers with vendor-level access can exploit this. The plugin must be updated to the latest version and vendor account security should be reinforced.
Azərbaycanca: StoreEngine WordPress pluginində parse_file_path funksiyası vasitəsilə Directory Traversal zəifliyi aşkar edilib. 2.1.1-ə qədər olan versiyalar təsir altındadır. Vendor səviyyəli autentifikasiyalı hücumçular bu boşluqdan istifadə edə bilər – plugin ən son versiyaya yenilənməli, vendor hesablarının təhlükəsizliyi gücləndirilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Through which function in the StoreEngine plugin is CVE-2026-15056 exploited?
This Directory Traversal vulnerability is exploited via the `parse_file_path` function.
What level of authentication must an attacker have to exploit CVE-2026-15056?
The attacker must have vendor-level authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.