CVE-2025-52708: WordPress HUSKY plugin <= 1.3.7 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY allows PHP Local File Inclusion. This issue affects HUSKY: from n/a through 1.3.7.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY woocommerce-products-filter allows PHP Local File Inclusion.This issue affects HUSKY: from n/a through <= 1.3.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52708?
CVE-2025-52708 is considered a critical vulnerability due to its potential for remote file inclusion and local file access.
How do I fix CVE-2025-52708?
To fix CVE-2025-52708, upgrade RealMag777 HUSKY to version 1.3.8 or later.
What types of attacks are possible with CVE-2025-52708?
CVE-2025-52708 allows attackers to perform local file inclusion attacks, potentially compromising the server.
Which versions of HUSKY are affected by CVE-2025-52708?
CVE-2025-52708 affects all versions of HUSKY from n/a to 1.3.7.
Is the WordPress HUSKY plugin also affected by CVE-2025-52708?
Yes, the WordPress HUSKY plugin is affected by CVE-2025-52708 up to version 1.3.7.