WordPress Plugin Vulnerabilities
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Description
The plugin does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the WordPress.org repo, including vulnerable plugins that have been closed.
This was previously reported (https://www.cve.org/CVERecord?id=CVE-2024-9707) and a patch was released in version 1.8.5, however, the vulnerability was not fixed correctly.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Daniel Rodriguez
Submitter
Daniel Rodriguez
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2024-12-10 (about 1 year ago)
Added
2024-12-10 (about 1 year ago)
Last Updated
2024-12-10 (about 1 year ago)