← WordPress Vulnerabilities
WordPress security by component

HUSKY

HUSKY is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: husky

CVE-2026-15244: HUSKY settings let Shop Managers include and execute local files

HUSKY before 1.4.1 concatenates a stored setting value into a file-inclusion path without removing directory traversal. A user with the Shop Manager capability can save a crafted path that selects an arbitrary local file; the plugin then includes and executes that file on every front-end request, including requests from unauthenticated visitors. The published record does not disclose the setting name, save action, include function or which writable local files can provide executable content.

PublishedAug 01, 2026
Known safe version1.4.1
Safe version
Aug 01, 2026 CVE-2026-15244
HUSKY settings let Shop Managers include and execute local files
HUSKY before 1.4.1 concatenates a stored setting value into a file-inclusion path without removing directory traversal. A user with the Shop Manager capability can save a crafted path that selects an arbitrary local file; the plugin then includes and executes that file on every front-end request, including requests from unauthenticated visitors. The published record does not disclose the setting name, save action, include function or which writable local files can provide executable content.
1.4.1
CVEPending
NVDPending