๐Ÿ” CVE Alert

CVE-2026-15244

UNKNOWN 0.0

HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.

Vendor unknown
Product husky
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown husky

Be the first to know when new unknown vulnerabilities affecting unknown husky are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / HUSKY
0 < 1.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7384ebb7-a581-45c7-ab48-0fdf30a1569d/

Credits

Meher Sudhakar Abbireddi WPScan