Hunk Companion <= 1.8.5 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

2024-12-10 00:00
Daniel Rodriguez

Strategic Overview

Status
Patched in 1.9.0
Affected PluginHunk Companion
Affected Version<= 1.8.5
CVSS9.8Critical
CVECVE-2024-11972
View all Hunk Companion vulnerabilities

Vulnerability Overview

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. This is a bypass to CVE-2024-9707.

Technical Analysis

REMEDIATION: Update to version 1.9.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C