Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
85Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 9.8epss 9.1%
de la publicación al arma0 días
Publicada en NVD11 oct
1ª PoC11 oct
VulnCheck11 oct
probabilidad de explotación
9.1%top 5% de las CVE
explotación observada
síVulnCheck
4 exploit(s) público(s)
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
themehunk · Hunk CompanionPoCs públicas encontradas — 4
githubgithub.com/RandomRobbieBF/CVE-2024-9707★ 1githubgithub.com/Nxploited/CVE-2024-9707-Poc★ 0vulncheckvulncheck.com/xdb/43421d90db76no verificadovulncheckvulncheck.com/xdb/22a917a30ac9no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/WordPressBugBounty/plugins-hunk-companion/blob/5a3cedc7b3d35d407b210e691c53c6cb400e4051/hunk-companion/import/app/app.php#L46https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3166501%40hunk-companion&new=3166501%40hunk-companion&sfp_email=&sfph_mail=https://wordpress.org/plugins/hunk-companion/https://www.wordfence.com/threat-intel/vulnerabilities/id/9c101fca-037c-4bed-9dc7-baa021a8b59c?source=cve