CVE Database /
CVE-2026-15244
CVE
CVE-2026-15244 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-15244
|
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Unknown
|
< 1.4.1
|
1.4.1 |
2026-07-17 |
—
|
CVE-2026-15244
The HUSKY plugin for WordPress, prior to version 1.4.1, fails to properly validate a stored setting when incorporating it into a file path, enabling users with shop manager privileges to force the inclusion and execution of local files on each website visit, regardless of user authentication status. This vulnerability is exploitable through front-end requests, making it accessible even to unauthenticated visitors.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings