← Back to browse · API

CVE-2024-9707

Severity
CRITICAL
CVSS
9.8
EPSS
0.09005
Risk score
42.35
CISA KEV
No
PoC
No
Published
2024-10-11
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-50100, GHSA-8CM3-4QFX-PWVC
Products
ThemeHunk:Hunk Companion 0 ≤1.8.4
Sources
euvd EUVD-2024-50100

Description

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

References