WordPress Plugin Vulnerabilities

Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation

Description

The plugin does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the WordPress.org repo, including vulnerable plugins that have been closed.

This was previously reported (https://www.cve.org/CVERecord?id=CVE-2024-9707) and a patch was released in version 1.8.5, however, the vulnerability was not fixed correctly.

Proof of Concept

Affects Plugins

Fixed in 1.9.0

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Daniel Rodriguez
Submitter
Daniel Rodriguez
Submitter website
Verified
Yes

Timeline

Publicly Published
2024-12-10 (about 1 year ago)
Added
2024-12-10 (about 1 year ago)
Last Updated
2024-12-10 (about 1 year ago)

Other