WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins

Post by Shane1145 »

Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks.

The flaw, tracked as CVE-2024-11972 (CVSS score: 9.8), affects all versions of the plugin prior to 1.9.0. The plugin has over 10,000 active installations.


https://thehackernews.com/2024/12/wordp ... -flaw.html
Post Reply