← Vulnerability feed

Vulnerability record · CVE-2024-11972 · published 31 December 2024

CVE-2024-11972: Hunk Companion WordPress plugin missing REST API authorization allows unauthenticated plugin installation

Themehunk · Hunk Companion

The Hunk Companion WordPress plugin before 1.9.0 fails to properly authorize some REST API endpoints. This lets unauthenticated requests install and activate arbitrary plugins from the WordPress.org repository, including closed vulnerable plugins. Because it is remotely reachable with no credentials, it is a serious site takeover risk.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0%
9.8CVSS 3.1 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, and high EPSS score indicating likely exploitation.

What it is

The Hunk Companion WordPress plugin before 1.9.0 fails to properly authorize some REST API endpoints. This lets unauthenticated requests install and activate arbitrary plugins from the WordPress.org repository, including closed vulnerable plugins. Because it is remotely reachable with no credentials, it is a serious site takeover risk.

Impact

An attacker can install and activate arbitrary plugins on the target WordPress site without authentication. This can be used to deploy vulnerable or malicious plugins, leading to full site compromise.

Attack surface

Reachable over the network through the plugin's REST API endpoints. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

No CISA KEV listing. EPSS is 0.54475 (98.963 percentile), indicating high predicted exploitation activity. The sole reference is tagged Exploit, suggesting public exploit information exists.

What to do

  • Update Hunk Companion to version 1.9.0 or later immediately.
  • If the plugin is not required, deactivate and remove it.
  • Restrict access to WordPress REST API endpoints where feasible using a WAF or server rules.
  • Audit installed plugins for unexpected or unauthorized additions.
  • Monitor WordPress.org plugin installation activity for anomalies.

Detection

  • Review web server and WordPress logs for unauthenticated POST requests to REST API endpoints associated with Hunk Companion.
  • Alert on unexpected plugin installation or activation events, especially for closed or vulnerable plugins.
  • Monitor for outbound requests to WordPress.org plugin download endpoints from the affected site.
  • Check file integrity of wp-content/plugins for new or modified plugin directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-11972 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-11972), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.