themehunk Vulnerabilities and Affected Products
Vulnerabilities associated with Hunk Companion.
Products
Clear product- Lead Form Builder & Contact Form4 vulnerabilities
- Contact Form & Lead Form Elementor Builder3 vulnerabilities
- Vayu Blocks – Website Builder for the Block Editor3 vulnerabilities
- Advance WordPress Search Plugin2 vulnerabilities
- advanced_wordpress_search2 vulnerabilities
- Big Store2 vulnerabilities
- Easy Mega Menu for WordPress – ThemeHunk2 vulnerabilities
- Gutenberg Blocks2 vulnerabilities
- Hunk Companion Plugin2 vulnerabilities
- Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce2 vulnerabilities
- Advance Product Search1 vulnerability
- Advance Product Search- Voice & Ajax Search for WooCommerce1 vulnerability
- Hunk Companion1 vulnerability
- hunk_companion1 vulnerability
- Oneline Lite1 vulnerability
- Open Shop1 vulnerability
- TH Login Registration1 vulnerability
- Th Shop Mania1 vulnerability
- TH Variation Swatches1 vulnerability
- th_shop_mania1 vulnerability
- ThemeHunk1 vulnerability
- Top Store1 vulnerability
- top_store1 vulnerability
- Variation Swatches for WooCommerce1 vulnerability
- Wishlist for WooCommerce1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-9707CRITICAL | Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/ActivationThe Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. | CVSS9.8v3.1 | EPSS9.01% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |