SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15244

HIGH · CVSS 7.2 EPSS 0.70%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The HUSKY WordPress plugin prior to version 1.4.1 is vulnerable to directory traversal attacks due to inadequate sanitization of stored setting values, allowing users with shop manager privileges to include and execute arbitrary local files. This vulnerability can be exploited on every front-end request, impacting even unauthenticated visitors. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-15244
Severity
HIGH
CVSS
7.2
EPSS
0.70%
WordPress

Original NVD Description

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.