9.8
CVE-2024-11972
- EPSS 91.25%
- Veröffentlicht 31.12.2024 06:15:23
- Zuletzt bearbeitet 17.05.2025 02:22:32
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Hunk Companion <= 1.8.5 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
Mögliche Gegenmaßnahme
Hunk Companion: Update to version 1.9.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Hunk Companion
Version
*-1.8.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themehunk ≫ Hunk Companion SwPlatformwordpress Version < 1.9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 91.25% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|