PoC Index

CVE-2024-11972

CRITICAL 9.8EPSS 54.5%

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
54.47% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical
Published
2024-12-31

Proof-of-concept exploits (3)

Nuclei templates (1)

ExploitDB entries (1)

References

Related