Vulnerability record · CVE-2024-11972 · published 31 December 2024
CVE-2024-11972: Hunk Companion WordPress plugin missing REST API authorization allows unauthenticated plugin installation
Themehunk · Hunk Companion
The Hunk Companion WordPress plugin before 1.9.0 fails to properly authorize some REST API endpoints. This lets unauthenticated requests install and activate arbitrary plugins from the WordPress.org repository, including closed vulnerable plugins. Because it is remotely reachable with no credentials, it is a serious site takeover risk.
Description
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and high EPSS score indicating likely exploitation.
What it is
The Hunk Companion WordPress plugin before 1.9.0 fails to properly authorize some REST API endpoints. This lets unauthenticated requests install and activate arbitrary plugins from the WordPress.org repository, including closed vulnerable plugins. Because it is remotely reachable with no credentials, it is a serious site takeover risk.
Impact
An attacker can install and activate arbitrary plugins on the target WordPress site without authentication. This can be used to deploy vulnerable or malicious plugins, leading to full site compromise.
Attack surface
Reachable over the network through the plugin's REST API endpoints. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
No CISA KEV listing. EPSS is 0.54475 (98.963 percentile), indicating high predicted exploitation activity. The sole reference is tagged Exploit, suggesting public exploit information exists.
What to do
- Update Hunk Companion to version 1.9.0 or later immediately.
- If the plugin is not required, deactivate and remove it.
- Restrict access to WordPress REST API endpoints where feasible using a WAF or server rules.
- Audit installed plugins for unexpected or unauthorized additions.
- Monitor WordPress.org plugin installation activity for anomalies.
Detection
- Review web server and WordPress logs for unauthenticated POST requests to REST API endpoints associated with Hunk Companion.
- Alert on unexpected plugin installation or activation events, especially for closed or vulnerable plugins.
- Monitor for outbound requests to WordPress.org plugin download endpoints from the affected site.
- Check file integrity of wp-content/plugins for new or modified plugin directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/4963560b-e4ae-451d-8f94-482779c415e4/ | ExploitThird Party Advisory |
Track CVE-2024-11972 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-11972), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.