CVE-2024-9707: Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9707?
CVE-2024-9707 is classified as a high severity vulnerability due to the potential for unauthorized plugin installation.
How do I fix CVE-2024-9707?
To fix CVE-2024-9707, update the Hunk Companion plugin to version 1.8.5 or later.
Who is affected by CVE-2024-9707?
All users of the Hunk Companion plugin for WordPress who are on versions up to and including 1.8.4 are affected by CVE-2024-9707.
What type of vulnerability is CVE-2024-9707?
CVE-2024-9707 is a security vulnerability characterized as an unauthorized access issue due to a missing capability check.
Can CVE-2024-9707 be exploited remotely?
Yes, CVE-2024-9707 can be exploited remotely as it allows unauthenticated attackers to install or activate plugins.