---
id: CVE-2026-15244
title: >-
  The HUSKY  WordPress plugin before 1.4.1 does not sanitize a stored setting
  value against directory traversal before concatenating it into a file
  inclusion path, allowing users with the shop manager capability to cause the
  inclusion and …
summary: >-
  The HUSKY  WordPress plugin before 1.4.1 does not sanitize a stored setting
  value against directory traversal before concatenating it into a file
  inclusion path, allowing users with the shop manager capability to cause the
  inclusion and …
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15244'
references:
  - url: 'https://wpscan.com/vulnerability/7384ebb7-a581-45c7-ab48-0fdf30a1569d/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.01148
epssPercentile: 0.65384
ingestedAt: '2026-08-02T05:17:47.626Z'
---

## Overview

The HUSKY  WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
