'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-08 | |
| Rule Name: | Hunk Companion Unauthenticated Plugin Installation Vulnerability (CVE-2024-11972) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed. | |
| Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://wpscan.com/vulnerability/4963560b-e4ae-451d-8f94-482779c415e4/ |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: https://wpscan.com/vulnerability/4963560b-e4ae-451d-8f94-482779c415e4/ |