The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
Metrics
Affected Vendors & Products
References
History
Sat, 17 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themehunk
Themehunk hunk Companion |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:themehunk:hunk_companion:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themehunk
Themehunk hunk Companion |
Tue, 31 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 31 Dec 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed. | |
| Title | Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-12-31T18:14:10.608Z
Reserved: 2024-11-28T19:29:06.929Z
Link: CVE-2024-11972
Updated: 2024-12-31T18:13:57.108Z
Status : Analyzed
Published: 2024-12-31T06:15:23.777
Modified: 2025-05-17T02:22:32.007
Link: CVE-2024-11972
No data.