peter bassill · operator
$ cve CVE-2024-11972 JSON

CVE-2024-11972 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 54.5% (pctl 99)

Patch early

A public exploit exists.

Description

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS54.48% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2024-12-31
Last modified2026-06-17

Affected (1)

VendorProduct
themehunkhunk companion

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD