SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin Hunk Companion Arbitrary File Upload

Category: WEB-ATTACKS      

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due tto a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint.


Relevant Information