Page 1 of 1

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins

Posted: Wed Feb 05, 2025 5:21 pm
by Shane1145
Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks.

The flaw, tracked as CVE-2024-11972 (CVSS score: 9.8), affects all versions of the plugin prior to 1.9.0. The plugin has over 10,000 active installations.


https://thehackernews.com/2024/12/wordp ... -flaw.html