SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin Hunk Companion Unauthenticated Plugin Installation

Category: WEB-ATTACKS      

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.


Relevant Information