WordPress security by component
HUSKY
Plugin description
HUSKY is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
huskyLatest vulnerability
CVE-2026-15244: HUSKY settings let Shop Managers include and execute local files
HUSKY before 1.4.1 concatenates a stored setting value into a file-inclusion path without removing directory traversal. A user with the Shop Manager capability can save a crafted path that selects an arbitrary local file; the plugin then includes and executes that file on every front-end request, including requests from unauthenticated visitors. The published record does not disclose the setting name, save action, include function or which writable local files can provide executable content.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-15244
HUSKY settings let Shop Managers include and execute local files
HUSKY before 1.4.1 concatenates a stored setting value into a file-inclusion path without removing directory traversal. A user with the Shop Manager capability can save a crafted path that selects an arbitrary local file; the plugin then includes and executes that file on every front-end request, including requests from unauthenticated visitors. The published record does not disclose the setting name, save action, include function or which writable local files can provide executable content.
|
1.4.1 |
CVEPending
NVDPending
|