CVE-2025-26890: WordPress HUSKY plugin <= 1.3.6.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY woocommerce-products-filter allows PHP Local File Inclusion.This issue affects HUSKY: from n/a through <= 1.3.6.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26890?
The severity of CVE-2025-26890 is high due to the potential for remote file inclusion and unauthorized access to sensitive files.
How do I fix CVE-2025-26890?
To fix CVE-2025-26890, upgrade the PluginUs.Net HUSKY to the latest version beyond 1.3.6.4.
What systems are affected by CVE-2025-26890?
CVE-2025-26890 affects PluginUs.Net HUSKY versions from n/a to 1.3.6.4.
What type of vulnerability is CVE-2025-26890?
CVE-2025-26890 is a Remote File Inclusion (RFI) vulnerability that allows attackers to include unintended files.
Can CVE-2025-26890 lead to data breaches?
Yes, CVE-2025-26890 can lead to data breaches if exploited, as it allows unauthorized access to local files on the server.