vendor:
Hunk Companion Plugin
by:
Jun Takemura
6.1
CVSS
HIGH
Unauthenticated Plugin Installation
119
CWE
Product Name: Hunk Companion Plugin
Affected Version From: 1.9
Affected Version To: 36770
Patch Exists: NO
Related CWE: CVE-2024-11972
CPE: a:themehunk:hunk_companion:1.9.0
Platforms Tested: Ubuntu
2024
Hunk Companion Plugin 1.9.0 – Unauthenticated Plugin Installation
The Hunk Companion plugin version 1.9.0 is vulnerable to unauthenticated plugin installation due to a flaw in the permission_callback for the /wp-json/hc/v1/themehunk-import endpoint. This vulnerability allows unauthorized attackers to install and activate any plugin from the WordPress.org repository.
Mitigation:
Update to the latest version of the Hunk Companion plugin to prevent exploitation of this vulnerability.