CVE-2024-9707 affects the Hunk Companion WordPress plugin (versions up to 1.8.4), allowing unauthenticated attackers to install and activate arbitrary plugins due to a missing capability check on a REST API endpoint. This critical vulnerability (CVSS 9.8) enables remote code execution if a subsequently installed plugin is also vulnerable. While not in CISA's KEV catalog, exploit intelligence indicates readily available Nuclei templates and significant community discussion, with multiple media outlets reporting active exploitation campaigns targeting this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.5CPE matchmatch criteria | cpe:2.3:a:themehunk:hunk_companion:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 1.8.4CPE match | cpe:2.3:a:themehunk:hunk_companion:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.