{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/products-filter-for-woocommerce-professional--1.4.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:husky:products_filter_for_woocommerce_professional:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92969"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Products Filter for WooCommerce Professional (\u003c= 1.4.4)"],"_cs_severities":["high"],"_cs_tags":["wordpress","lfi","web-application"],"_cs_type":"advisory","_cs_vendors":["HUSKY"],"content_html":"\u003cp\u003eThe HUSKY - Products Filter for WooCommerce Professional plugin for WordPress contains a critical Local File Inclusion (LFI) vulnerability tracked as CVE-2026-92969. This flaw affects all versions up to and including 1.4.4. The vulnerability stems from improper validation of the 'shortcode' parameter in the plugin's front-end processing logic. While the plugin implements a nonce check using 'woof_front_nonce', this value is exposed to all site visitors via inline JavaScript on every front-end page, rendering the security control ineffective. Consequently, unauthenticated attackers can leverage this LFI to include and execute arbitrary PHP files located on the web server. This access enables attackers to bypass access controls, exfiltrate sensitive data, or achieve full Remote Code Execution (RCE) if they can successfully place a malicious payload within a file accessible to the server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the underlying web server hosting the WordPress instance. This can lead to total site compromise, including database exfiltration, unauthorized modification of site content, and potential lateral movement within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the HUSKY - Products Filter for WooCommerce Professional plugin to the latest available patched version immediately. Monitor web server access logs for anomalous POST or GET requests targeting the WooCommerce filter endpoints containing directory traversal sequences or references to unexpected file extensions in the 'shortcode' parameter.\u003c/p\u003e\n","date_modified":"2026-09-22T08:34:45Z","date_published":"2026-09-22T08:34:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-husky-lfi/","summary":"The HUSKY Products Filter for WooCommerce Professional plugin (\u003c= 1.4.4) is vulnerable to unauthenticated Local File Inclusion (LFI) due to inadequate nonce protection, allowing remote code execution via arbitrary PHP file inclusion.","title":"Local File Inclusion in HUSKY Products Filter for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-husky-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Products Filter for WooCommerce Professional (\u003c= 1.4.4)","version":"https://jsonfeed.org/version/1.1"}