CVE

CVE-2026-15244 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15244 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 1.4.1 1.4.1 2026-07-17

CVE-2026-15244

The HUSKY plugin for WordPress, prior to version 1.4.1, fails to properly validate a stored setting when incorporating it into a file path, enabling users with shop manager privileges to force the inclusion and execution of local files on each website visit, regardless of user authentication status. This vulnerability is exploitable through front-end requests, making it accessible even to unauthenticated visitors.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.