What is CVE-2026-15244?
This vulnerability exists in the HUSKY WordPress plugin prior to version 1.4.1. It fails to sanitize a stored setting value against directory traversal, allowing users with 'shop manager' capability to include and execute arbitrary local files via a malicious path. Immediate update to the latest patched version is required.
Azərbaycanca: Bu boşluq, HUSKY WordPress plugin-inin 1.4.1 versiyasından əvvəlki versiyalarında aşkar edilmişdir. Saxlanılan parametr dəyərinin directory traversal əleyhinə sanitizə edilməməsi, 'shop manager' icazəsi olan istifadəçilərə lokal fayl daxil etmə (LFI) və icra etdirməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What user permission level is required to exploit CVE-2026-15244?
Only authenticated users with 'shop manager' capability can exploit this vulnerability.
Which version of the HUSKY plugin fixes CVE-2026-15244?
Version 1.4.1 and above address this vulnerability. Prior versions are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.