The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is exploitable by unauthenticated users because the only access control is a nonce check against woof_front_nonce, which is publicly emitted into inline JavaScript on every front-end page and is therefore obtainable by any site visitor without authentication.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The HUSKY – Products Filter for WooCommerce Professional plugin contains a critical Local File Inclusion (LFI) vulnerability in its shortcode parameter handling that allows unauthenticated attackers to include and execute arbitrary PHP files on vulnerable servers. With a CVSS score of 8.1, this vulnerability is particularly dangerous because it requires no authentication, has a network attack vector, and can lead to complete server compromise. Any WordPress site running versions 1.4.4 or earlier of this plugin is at immediate risk, with attackers able to execute malicious PHP code, access sensitive data, bypass access controls, or establish persistent backdoors on the affected system.
While this CVE currently maps to zero Casky skills (indicating limited MITRE ATT&CK technique coverage in the initial disclosure), practitioners using Casky.ai would typically detect LFI attack patterns through skills aligned with techniques such as T1083 (File and Directory Discovery), T1005 (Data from Local System), and T1059 (Command and Scripting Interpreter). Claude AI's extended reasoning would help security teams identify suspicious shortcode parameters containing file path traversal sequences (../, ..\, or absolute paths), detect attempts to include sensitive files like wp-config.php or /etc/passwd, and recognize the execution of dynamically loaded PHP files through web server logs. When investigating this vulnerability, practitioners should monitor for HTTP requests with encoded or obfuscated file paths in plugin parameters and correlate them with unexpected PHP execution patterns in server logs or web access records.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-92969. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation