CyberRota Analysis
AI-GeneratedThe HUSKY WordPress plugin prior to version 1.4.1 is vulnerable to directory traversal attacks due to inadequate sanitization of stored setting values, allowing users with shop manager privileges to include and execute arbitrary local files. This vulnerability can be exploited on every front-end request, impacting even unauthenticated visitors. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.