First published: Thu Mar 27 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginUs.Net HUSKY allows PHP Local File Inclusion.This issue affects HUSKY: from n/a through 1.3.6.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
PluginUs.Net HUSKY | >=n/a<=1.3.6.4 | |
WordPress | <=1.3.6.4 |
Update the WordPress HUSKY plugin to the latest available version (at least 1.3.6.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-26890 is high due to the potential for remote file inclusion and unauthorized access to sensitive files.
To fix CVE-2025-26890, upgrade the PluginUs.Net HUSKY to the latest version beyond 1.3.6.4.
CVE-2025-26890 affects PluginUs.Net HUSKY versions from n/a to 1.3.6.4.
CVE-2025-26890 is a Remote File Inclusion (RFI) vulnerability that allows attackers to include unintended files.
Yes, CVE-2025-26890 can lead to data breaches if exploited, as it allows unauthorized access to local files on the server.