Showing 1 vulnerability on this page for Hunk Companion

Signals CISA KEV Ransomware Nuclei
themehunk vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CWE-862Oct 11, 20241 related artifact
CVSS9.8v3.1EPSS9.01%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX