The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
History

Sat, 17 May 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Themehunk
Themehunk hunk Companion
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:themehunk:hunk_companion:*:*:*:*:*:wordpress:*:*
Vendors & Products Themehunk
Themehunk hunk Companion

Tue, 31 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 31 Dec 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
Title Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-12-31T18:14:10.608Z

Reserved: 2024-11-28T19:29:06.929Z

Link: CVE-2024-11972

cve-icon Vulnrichment

Updated: 2024-12-31T18:13:57.108Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-31T06:15:23.777

Modified: 2025-05-17T02:22:32.007

Link: CVE-2024-11972

cve-icon Redhat

No data.