CVE-2024-11972: Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11972?
CVE-2024-11972 has been classified as a high severity vulnerability due to unauthorized access to critical functionality of the Hunk Companion WordPress plugin.
How do I fix CVE-2024-11972?
To fix CVE-2024-11972, update the Hunk Companion WordPress plugin to version 1.9.0 or later.
What types of systems are affected by CVE-2024-11972?
CVE-2024-11972 affects WordPress installations using the Hunk Companion plugin versions prior to 1.9.0.
What kind of exploit is associated with CVE-2024-11972?
CVE-2024-11972 allows unauthenticated requests to install or activate arbitrary versions of the Hunk Companion plugin.
Is there a mitigation for CVE-2024-11972 besides updating?
Currently, there is no known mitigation for CVE-2024-11972 other than updating to the patched version.