CVE-2026-15244: HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15244?
CVE-2026-15244 has a risk rating of 68.
How do I fix CVE-2026-15244?
To mitigate CVE-2026-15244, update the HUSKY Products Filter Professional for WooCommerce to version 1.4.1 or later.
Who is affected by CVE-2026-15244?
Users with the shop manager capability in the HUSKY Wordpress plugin prior to version 1.4.1 are affected by CVE-2026-15244.
What is the impact of CVE-2026-15244?
CVE-2026-15244 allows unauthorized users to include and execute arbitrary local files due to directory traversal vulnerabilities.
What does CVE-2026-15244 pertain to?
CVE-2026-15244 pertains to a local file inclusion vulnerability in the HUSKY Products Filter Professional for WooCommerce plugin.