CVE-2024-11972 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 54.5% (pctl 99)
Patch early
A public exploit exists.
Description
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 54.48% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-12-31 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| themehunk | hunk companion |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation | 2025-04-18 |
→ the Explorer · watch your stack · NVD